CISA's list that day
10 March 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Ivanti Endpoint Manager (EPM) and Advantive VeraCore. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-13159Absolute Path Traversal | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2024-13160Absolute Path Traversal | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.91 | 0.91 | ||
| CVE-2024-13161Absolute Path Traversal | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.90 | 0.90 | ||
| CVE-2025-25181SQL Injection | Advantive VeraCore | Patch this weekEPSS 0.56 | 0.56 | ||
| CVE-2024-57968Unrestricted File Upload | Advantive VeraCore | Patch soon | 0.32 |