CISA's list that day

29 April 2025

On CISA added 1 vulnerability to its list of exploited vulnerabilities: CVE-2025-31324 in SAP NetWeaver. US federal agencies must fix it by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-31324Unrestricted File UploadSAP NetWeaverPatch this weekRansomware use; EPSS 0.990.99

Other changes that day

  1. CVE-2015-2291 Intel Ethernet Diagnostics Driver for WindowsRansomware use: Unknown to Known.
  2. CVE-2025-3928 Commvault Web ServerDeadline moved from 17 May 2025 to 19 May 2025.
  3. CVE-2025-30406 Gladinet CentreStackEdited: notes, description and name.