CISA's list that day
2 May 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Yiiframework Yii and Commvault Command Center. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-58136Improper Protection of Alternate Path | Yiiframework Yii | Patch this weekEPSS 0.88 | 0.88 | ||
| CVE-2025-34028Path Traversal | Commvault Command Center | Patch this weekEPSS 0.98 | 0.98 |
Other changes that day
- CVE-2025-22457 Ivanti Connect Secure, Policy Secure, and ZTA GatewaysRenamed from Connect Secure, Policy Secure and ZTA Gateways to Connect Secure, Policy Secure, and ZTA Gateways. Edited: notes, description and name.