CISA's list that day
13 May 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-30397Scripting Engine Type Confusion | Microsoft Windows | Patch soon | 0.27 | ||
| CVE-2025-32706Common Log File System (CLFS) Driver Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2025-32709Ancillary Function Driver for WinSock Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2025-30400DWM Core Library Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2025-32701Common Log File System (CLFS) Driver Use-After-Free | Microsoft Windows | Patch soon | 0.01 |