CISA's list that day

6 February 2025

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Sophos XG Firewall, Sophos CyberoamOS, Audinate Dante Discovery and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-21413Outlook Improper Input ValidationMicrosoft Office OutlookPatch this weekEPSS 0.950.95
CVE-2025-0411Mark of the Web Bypass7-Zip 7-ZipPatch this weekEPSS 0.670.67
CVE-2020-29574(CROS) SQL InjectionSophos CyberoamOSPatch this weekRansomware use0.05
CVE-2020-15069Buffer OverflowSophos XG FirewallPatch soon0.11
CVE-2022-23748Process ControlAudinate Dante DiscoveryPatch soon0.09