CISA's list that day

15 May 2025

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in DrayTek Vigor Routers, Google Chromium and SAP NetWeaver. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-12987OS Command InjectionDrayTek Vigor RoutersPatch this weekEPSS 0.980.98
CVE-2025-42999DeserializationSAP NetWeaverPatch this weekRansomware use0.14
CVE-2025-4664Loader Insufficient Policy EnforcementGoogle ChromiumRemoved from CISA's list0.06

Other changes that day

  1. CVE-2025-31324 SAP NetWeaverRansomware use: Unknown to Known.