CISA's list that day
19 May 2025
On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in ZKTeco BioTime, MDaemon Email Server, Synacor Zimbra Collaboration Suite (ZCS) and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-4427Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-4428Code Injection | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| CVE-2023-38950Path Traversal | ZKTeco BioTime | Patch this weekEPSS 0.92 | 0.92 | ||
| CVE-2024-11182Cross-Site Scripting (XSS) | MDaemon Email Server | Patch soon | 0.18 | ||
| CVE-2024-27443Cross-Site Scripting (XSS) | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.24 | ||
| CVE-2025-27920Directory Traversal | Srimax Output Messenger | Patch soon | 0.02 |