CISA's list that day
6 February 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Sophos XG Firewall, Sophos CyberoamOS, Audinate Dante Discovery and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-21413Outlook Improper Input Validation | Microsoft Office Outlook | Patch this weekEPSS 0.95 | 0.95 | ||
| CVE-2025-0411Mark of the Web Bypass | 7-Zip 7-Zip | Patch this weekEPSS 0.67 | 0.67 | ||
| CVE-2020-29574(CROS) SQL Injection | Sophos CyberoamOS | Patch this weekRansomware use | 0.05 | ||
| CVE-2020-15069Buffer Overflow | Sophos XG Firewall | Patch soon | 0.11 | ||
| CVE-2022-23748Process Control | Audinate Dante Discovery | Patch soon | 0.09 |