CISA's list that day

2 May 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Yiiframework Yii and Commvault Command Center. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-58136Improper Protection of Alternate PathYiiframework YiiPatch this weekEPSS 0.880.88
CVE-2025-34028Path TraversalCommvault Command CenterPatch this weekEPSS 0.980.98

Other changes that day

  1. CVE-2025-22457 Ivanti Connect Secure, Policy Secure, and ZTA GatewaysRenamed from Connect Secure, Policy Secure and ZTA Gateways to Connect Secure, Policy Secure, and ZTA Gateways. Edited: notes, description and name.