CISA's list that day

25 February 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Partner Center. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2023-34192Cross-Site Scripting (XSS)Synacor Zimbra Collaboration Suite (ZCS)Patch this weekEPSS 0.770.77
CVE-2024-49035Improper Access ControlMicrosoft Partner CenterPatch soon0.01

Other changes that day

  1. CVE-2022-24682 Synacor Zimbra Collaborate Suite (ZCS)Renamed from Zimbra Webmail to Zimbra Collaborate Suite (ZCS). Edited: description and name.
  2. CVE-2024-24919 Check Point Quantum Security GatewaysRansomware use: Unknown to Known.