CISA's list that day

19 May 2025

On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in ZKTeco BioTime, MDaemon Email Server, Synacor Zimbra Collaboration Suite (ZCS) and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-4427Authentication BypassIvanti Endpoint Manager Mobile (EPMM)Patch this weekMetasploit module; EPSS 0.990.99
CVE-2025-4428Code InjectionIvanti Endpoint Manager Mobile (EPMM)Patch this weekMetasploit module; EPSS 0.870.87
CVE-2023-38950Path TraversalZKTeco BioTimePatch this weekEPSS 0.920.92
CVE-2024-11182Cross-Site Scripting (XSS)MDaemon Email ServerPatch soon0.18
CVE-2024-27443Cross-Site Scripting (XSS)Synacor Zimbra Collaboration Suite (ZCS)Patch soon0.24
CVE-2025-27920Directory TraversalSrimax Output MessengerPatch soon0.02