CISA's list that day

7 April 2025

On CISA added 1 vulnerability to its list of exploited vulnerabilities: CVE-2025-31161 in CrushFTP. US federal agencies must fix it by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-31161Authentication BypassCrushFTP CrushFTPPatch this weekRansomware use; EPSS 0.990.99

Other changes that day

  1. CVE-2018-8639 Microsoft WindowsRansomware use: Unknown to Known.
  2. CVE-2022-42475 Fortinet FortiOSRansomware use: Unknown to Known.
  3. CVE-2024-3400 Palo Alto Networks PAN-OSRansomware use: Unknown to Known.
  4. CVE-2024-30051 Microsoft DWM Core LibraryRansomware use: Unknown to Known.
  5. CVE-2024-38094 Microsoft SharePointRansomware use: Unknown to Known.
  6. CVE-2025-22457 Ivanti Connect Secure, Policy Secure, and ZTA GatewaysEdited: required action.