CISA's list that day
30 October 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in XWiki Platform and Broadcom VMware Aria Operations and VMware Tools. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-24893Eval Injection | XWiki Platform | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-41244Privilege Defined with Unsafe Actions | Broadcom VMware Aria Operations and VMware Tools | Patch soon | 0.08 |