CISA's list that day

18 March 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Fortinet FortiOS and FortiProxy and tj-actions changed-files GitHub Action. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-30066tj-actions/changed-files GitHub Action Embedded Malicious Codetj-actions changed-files GitHub ActionPatch this weekEPSS 0.720.72
CVE-2025-24472Authentication BypassFortinet FortiOS and FortiProxyPatch this weekRansomware use0.07

Other changes that day

  1. CVE-2023-23376 Microsoft WindowsRansomware use: Unknown to Known.
  2. CVE-2023-48365 Qlik SenseRansomware use: Unknown to Known.
  3. CVE-2024-45195 Apache OFBizEdited: notes.
  4. CVE-2024-55591 Fortinet FortiOS and FortiProxyRansomware use: Unknown to Known.
  5. CVE-2025-24984 Microsoft WindowsEdited: description.
  6. CVE-2025-24985 Microsoft WindowsEdited: weakness list and description.
  7. CVE-2025-24991 Microsoft WindowsEdited: description.
  8. CVE-2025-24993 Microsoft WindowsEdited: description.
  9. CVE-2025-26633 Microsoft WindowsEdited: description.