Vulnerability Report for the year 2025

All vulnerability reports
This report was generated with the help of AI, leveraging the VulnMCP Model Context Protocol server connected to Vulnerability-Lookup. The underlying data was aggregated from the twelve monthly reports published throughout 2025 and from the live Vulnerability-Lookup API.

Introduction

The 2025 threat landscape was characterised by sustained pressure on enterprise infrastructure, edge devices, and developer tooling. Attackers continued to weaponise newly disclosed vulnerabilities within hours of publication, while a long tail of unpatched legacy IoT and edge devices (D-Link, Zyxel, DASAN, Huawei, Realtek, Netgear) kept generating massive exploitation noise. Several flagship incidents shaped the year: the SAP NetWeaver Visual Composer zero-day exploitation in April, the SharePoint “ToolShell” campaign in July, the NetScaler “CitrixBleed 2” saga from June onward, the Oracle E-Business Suite exploitation tied to the Cl0p activity in October, the WSUS critical (CVE-2025-59287) in October-November, the FortiWeb authentication bypasses in November, and the dramatic React Server Components (“React2Shell”) surge in December.

This year-in-review consolidates the twelve monthly reports covering 2025 and aggregates the data collected by Vulnerability-Lookup. Sources used to build this report include:

This report was generated with AI assistance via VulnMCP, the Model Context Protocol server that exposes Vulnerability-Lookup capabilities to AI agents: https://github.com/vulnerability-lookup/VulnMCP.

The Year at a Glance

The charts below summarise publication trends and the ecosystem most affected throughout 2025.

Evolution of CVE publication

Evolution of CVE publications in 2025

Top 10 CVE Assigners of the Year

Top 10 CVE assigners in 2025

Top 10 Weaknesses (CWE) of the Year

Top 10 weaknesses (CWE) observed in 2025

Top 10 Vendors in 2025

Top 10 vendors by sightings in 2025

Recurring themes

2025 delivered an unusually high volume of actively exploited vulnerabilities. Recurring themes across the year include:

In total, our community recorded tens of thousands of sightings in 2025, with hundreds of patches released, dozens of public proofs of concept, and numerous in-the-wild exploitations confirmed by The Shadowserver Foundation honeypot network, CISA KEV additions, and contributor reports.

Top 50 Vulnerabilities of the Year

Most-sighted vulnerabilities recorded by Vulnerability-Lookup between 2025-01-01 and 2025-12-31. Severities are derived from the VLAI classifier.

VulnerabilitySighting CountVendorProductVLAI Severity
CVE-2025-551821138Metareact-server-dom-webpackCritical
CVE-2015-2051726D-LinkDIR-645High
CVE-2017-18368710ZyXELP660HN-T1ACritical
CVE-2025-5777671NetScalerADCCritical
CVE-2018-10562627DASAN NetworksGPON RouterCritical
CVE-2025-53770619MicrosoftSharePoint Enterprise Server 2016Critical
CVE-2025-31324566SAPSAP NetWeaver (Visual Composer)Critical
CVE-2018-14774542SymfonyHttpKernelMedium
CVE-2025-0108524Palo Alto NetworksPAN-OS / Cloud NGFWHigh
CVE-2021-44228493Apache Software FoundationApache Log4j2Critical
CVE-2023-20198472CiscoCisco IOS XE SoftwareHigh
CVE-2017-17215462HuaweiHG532Critical
CVE-2017-9841444PHPUnitPHPUnitCritical
CVE-2016-1555437NetgearWNAP320Critical
CVE-2014-8361435RealtekRealtek SDKCritical
CVE-2023-22527434AtlassianConfluence Data CenterCritical
CVE-2019-12780429BelkinWemo Crock-PotHigh
CVE-2025-29927427VercelNext.jsCritical
CVE-2024-3721426TBKDVR-4104 / DVR-4216Medium
CVE-2016-6277424NetgearD6220 / R-seriesHigh
CVE-2025-59287418MicrosoftWindows Server (WSUS)Critical
CVE-2016-10372418eirD1000 modemCritical
CVE-2019-1653408CiscoSmall Business RV320/RV325High
CVE-2021-26855401MicrosoftExchange Server (ProxyLogon)Critical
CVE-2021-42013391Apache Software FoundationApache HTTP ServerCritical
CVE-2023-0656380SonicWallSonicOSHigh
CVE-2023-42793377JetBrainsTeamCityCritical
CVE-2018-13379375FortinetFortiOS / FortiProxyCritical
CVE-2025-0282369IvantiConnect SecureCritical
CVE-2022-26134366AtlassianConfluence Data CenterCritical
CVE-2023-38646366MetabaseMetabaseCritical
CVE-2020-25506360D-LinkDNS-320 NASHigh
CVE-2018-7600355DrupalDrupal Core (Drupalgeddon 2)Critical
CVE-2024-28995348SolarWindsServ-UHigh
CVE-2023-23752343Joomla!Joomla! CMSHigh
CVE-2024-36401341OSGeoGeoServer / GeoToolsCritical
CVE-2022-22274335SonicWallSonicOSHigh
CVE-2024-4577333PHP GroupPHPCritical
CVE-2020-8191328CitrixADC / GatewayMedium
CVE-2025-61882327Oracle CorporationOracle Concurrent Processing (EBS)Critical
CVE-2011-3600322ApacheOFBizHigh
CVE-2021-32030320ASUSGT-AC2900 / Lyra Mini RoutersHigh
CVE-2023-26801318LB-LINKBL-AC1900 / BL-WR9000 routersHigh
CVE-2019-17506312D-LinkDIR-868L / DIR-817LWHigh
CVE-2025-24813307Apache Software FoundationApache TomcatCritical
CVE-2025-8088307win.rar GmbHWinRARHigh
CVE-2024-24919299Check PointQuantum Security GatewaysHigh
CVE-2016-10108290Western DigitalMyCloud NASHigh
CVE-2021-3129284LaravelIgnitionCritical
CVE-2025-32433282ErlangOTP (SSH)Critical

Top 10 Vulnerabilities per Month

Aggregated from the published monthly reports. The metrics differ slightly across months (some months use sighting counts, others a curated Top ranking).

January 2025

Top vulnerabilities sourced from the January 2025 report:

VulnerabilityVendorProductSeverity
CVE-2025-0282IvantiConnect Secure9.0 (Critical)
CVE-2024-55591FortinetFortiOS9.8 (Critical)
CVE-2024-49113MicrosoftWindows 10 (LDAP)7.5 (High)
CVE-2015-2051D-LinkDIR-6458.8 (High)
CVE-2025-24085ApplevisionOS / iOS7.3 (High)
CVE-2025-0283IvantiConnect Secure7.0 (High)
CVE-2018-10562DASAN NetworksGPON Router9.8 (Critical)
CVE-2017-17215HuaweiHG5328.8 (High)
CVE-2024-7344RadixSmartRecovery8.2 (High)
CVE-2024-50603AviatrixController10.0 (Critical)

February 2025

Top vulnerabilities sourced from the February 2025 report:

VulnerabilityVendorProductSeverity
CVE-2025-0282IvantiConnect Secure9.0 (Critical)
CVE-2024-55591FortinetFortiOS9.8 (Critical)
CVE-2024-49113MicrosoftWindows 10 (LDAP)7.5 (High)
CVE-2015-2051D-LinkDIR-6459.8 (Critical)
CVE-2017-18368ZyXELP660HN-T1A9.8 (Critical)
CVE-2025-0283IvantiConnect Secure7.0 (High)
CVE-2024-7344RadixSmartRecovery8.2 (High)
CVE-2017-17215HuaweiHG5328.8 (High)
CVE-2018-10562DASAN NetworksGPON Router9.8 (Critical)
CVE-2024-50603AviatrixController10.0 (Critical)

March 2025

Top vulnerabilities sourced from the March 2025 report:

VulnerabilityVendorProductSightingsSeverity
CVE-2025-29927VercelNext.js1679.1 (Critical)
CVE-2025-24813Apache Software FoundationApache Tomcat1289.2 (Critical)
CVE-2025-1974Kubernetesingress-nginx869.8 (Critical)
CVE-2024-4577PHP GroupPHP839.8 (Critical)
CVE-2025-22224VMwareESXi809.3 (Critical)
CVE-2025-24201AppleiOS / iPadOS797.0 (High)
CVE-2025-2783GoogleChrome728.3 (High)
CVE-2025-30066tj-actionschanged-files678.6 (High)
CVE-2017-18368ZyXELP660HN-T1A609.8 (Critical)
CVE-2015-2051D-LinkDIR-645608.8 (High)

April 2025

Top vulnerabilities sourced from the April 2025 report:

VulnerabilityVendorProductSightingsSeverity
CVE-2025-22457IvantiConnect Secure1889.0 (Critical)
CVE-2025-32433ErlangOTP (SSH)11910 (Critical)
CVE-2025-31161CrushFTPCrushFTP1089.8 (Critical)
CVE-2025-31324SAPNetWeaver Visual Composer10110 (Critical)
CVE-2025-29824MicrosoftWindows (CLFS)857.8 (High)
CVE-2025-24054MicrosoftWindows (NTLM)796.5 (Medium)
CVE-2025-30406GladinetCentreStack649.0 (Critical)
CVE-2025-24200AppleiPadOS616.1 (Medium)
CVE-2017-18368ZyXELP660HN-T1A609.8 (Critical)
CVE-2015-2051D-LinkDIR-645608.8 (High)

May 2025

Top vulnerabilities sourced from the May 2025 report:

VulnerabilityVendorProductVLAI Severity
CVE-2025-31324SAPNetWeaver Visual ComposerCritical
CVE-2025-4427IvantiEndpoint Manager MobileCritical
CVE-2025-37899LinuxLinux kernel (ksmbd)High
CVE-2025-4428IvantiEndpoint Manager MobileHigh
CVE-2025-32756FortinetFortiVoiceCritical
CVE-2025-4664GoogleChromeMedium
CVE-2025-20188CiscoIOS XE SoftwareCritical
CVE-2017-18368ZyXELP660HN-T1ACritical
CVE-2015-2051D-LinkDIR-645Critical
CVE-2024-38475Apache Software FoundationHTTP ServerCritical

June 2025

Top vulnerabilities sourced from the June 2025 report:

VulnerabilityVendorProductVLAI Severity
CVE-2025-33053MicrosoftWindows (WebDAV)High
CVE-2025-49113RoundcubeWebmailHigh
CVE-2025-5777NetScalerADC (“CitrixBleed 2”)Critical
CVE-2025-5419GoogleChromeHigh
CVE-2025-2783GoogleChromeHigh
CVE-2025-6019Red HatRed Hat Enterprise LinuxMedium
CVE-2025-33073MicrosoftWindows SMBHigh
CVE-2025-6543NetScalerADCCritical
CVE-2015-2051D-LinkDIR-645Critical
CVE-2017-18368ZyXELP660HN-T1ACritical

July 2025

Top vulnerabilities sourced from the July 2025 report:

VulnerabilityVendorProductSightingsVLAI Severity
CVE-2025-53770MicrosoftSharePoint (“ToolShell”)416Critical
CVE-2025-5777NetScalerADC267Critical
CVE-2025-25257FortinetFortiWeb145Critical
CVE-2025-6554GoogleChrome130High
CVE-2025-47812wftpserverWing FTP Server129Critical
GHSA-269G-PWP5-87PPjunit-teamJUnit4120Medium
CVE-2025-53771MicrosoftSharePoint104Medium
CVE-2025-49706MicrosoftSharePoint96Medium
GHSA-78WR-2P64-HPWJApache Software FoundationApache Commons IO85Medium
GHSA-5MG8-W23W-74H3Google LLCGuava84Low

August 2025

Top vulnerabilities sourced from the August 2025 report:

VulnerabilityVendorProductSightingsVLAI Severity
CVE-2025-8088win.rar GmbHWinRAR193High
CVE-2025-53786MicrosoftExchange Server175High
CVE-2025-43300ApplemacOS / iOS128Medium
CVE-2025-6543NetScalerADC111Critical
CVE-2025-25256FortinetFortiSIEM79Critical
CVE-2025-9074DockerDocker Desktop65Critical
CVE-2015-2051D-LinkDIR-64562Critical
CVE-2017-18368ZyXELP660HN-T1A61Critical
CVE-2025-31324SAPNetWeaver Visual Composer59Critical
CVE-2025-5777NetScalerADC52Critical

September 2025

Top vulnerabilities sourced from the September 2025 report:

VulnerabilityVendorProductSightingsVLAI Severity
CVE-2025-10585GoogleChrome94High
CVE-2025-10035FortraGoAnywhere MFT79Critical
CVE-2025-42957SAPS/4HANA71Critical
CVE-2025-55241MicrosoftEntra68High
CVE-2025-54236AdobeCommerce64Critical
CVE-2024-50264LinuxLinux kernel60High
CVE-2015-2051D-LinkDIR-64558High
CVE-2023-51767OpenSSHOpenSSH57High
CVE-2017-18368ZyXELP660HN-T1A57Critical
CVE-2025-43300AppleiOS / iPadOS54High

October 2025

Top vulnerabilities sourced from the October 2025 report:

VulnerabilityVendorProductSightingsVLAI Severity
CVE-2025-61882Oracle CorporationOracle Concurrent Processing (EBS)241Critical
CVE-2025-59287MicrosoftWindows Server (WSUS)235Critical
CVE-2025-49844RedisRedis106Critical
CVE-2025-59489Unity3DUnity Editor98High
CVE-2025-61884Oracle CorporationOracle Configurator95High
CVE-2025-54236AdobeCommerce94Critical
CVE-2025-55315MicrosoftASP.NET Core 8.075High
CVE-2015-2051D-LinkDIR-64564High
CVE-2025-20352CiscoIOS63High
CVE-2017-18368ZyXELP660HN-T1A63Critical

November 2025

Top vulnerabilities sourced from the November 2025 report:

VulnerabilityVendorProductSightingsVLAI Severity
CVE-2025-64446FortinetFortiWeb105Critical
CVE-2025-59287MicrosoftWindows Server (WSUS)88Critical
CVE-2025-21042Samsung MobileSamsung Mobile Devices86High
CVE-2025-58034FortinetFortiWeb84High
CVE-2025-13223GoogleChrome84High
CVE-2023-20198CiscoIOS XE Software71High
CVE-2025-61757Oracle CorporationIdentity Manager67Critical
CVE-2025-110017-Zip7-Zip65High
CVE-2025-12480TrioFoxTrioFox64Critical
CVE-2015-2051D-LinkDIR-64559High

December 2025

Top vulnerabilities sourced from the December 2025 report:

VulnerabilityVendorProductSightingsVLAI Severity
CVE-2025-55182Metareact-server-dom-webpack (“React2Shell”)852Critical
CVE-2025-14847MongoDB Inc.MongoDB Server204High
CVE-2025-20393CiscoCisco Secure Email89Critical
CVE-2015-2051D-LinkDIR-64562High
CVE-2017-18368ZyXELP660HN-T1A62Critical
CVE-2025-14733WatchGuardFireware OS60Critical
CVE-2025-66516Apache Software FoundationApache Tika core57High
CVE-2018-10562DASAN NetworksGPON Router56Critical
CVE-2025-40602SonicWallSMA100053Medium
CVE-2025-59718FortinetFortiSwitchManager53Critical

Known Exploited Vulnerabilities (CISA, CIRCL, EUVD)

KEV catalogs aggregated by Vulnerability-Lookup. The monthly reports formally introduced a dedicated Known Exploited Vulnerabilities section starting in September 2025. The entries below mirror what was published in each monthly report between September and December 2025. Earlier 2025 KEV additions (January–August) are tracked in the live CISA and EUVD catalogs but were not summarised at the time. CIRCL is the publisher of Vulnerability-Lookup and curates KEV data from CISA, EUVD/ENISA, and ad-hoc community sources.

CISA KEV

September 2025

CVE IDDate AddedVendorProductVLAI Severity
CVE-2025-5968929/09/25CiscoIOSMedium
CVE-2025-1003529/09/25FortraGoAnywhere MFTCritical
CVE-2025-3246329/09/25Sudo projectSudoHigh
CVE-2021-2131129/09/25vranaadminerHigh
CVE-2025-2035229/09/25CiscoIOSHigh
CVE-2025-2033325/09/25CiscoASA SoftwareCritical
CVE-2025-2036225/09/25CiscoASA SoftwareMedium
CVE-2025-1058523/09/25GoogleChromeHigh
CVE-2025-508611/09/25Dassault SystèmesDELMIA AprisoCritical
CVE-2025-5369004/09/25SitecoreExperience Manager (XM)Critical
CVE-2025-4854304/09/25GoogleAndroidHigh
CVE-2025-3835204/09/25LinuxLinux kernelHigh
CVE-2023-5022403/09/25TP-LinkTL-WR841NMedium
CVE-2025-937703/09/25TP-Link Systems Inc.Archer C7(EU) V2High
CVE-2020-2436302/09/25TP-LinkTL-WA855REHigh

October 2025

CVE IDDate AddedVendorProductVLAI Severity
CVE-2025-4124430/10/25VMwareVCF operationsHigh
CVE-2025-2489330/10/25XWikixwiki-platformCritical
CVE-2025-620528/10/25Dassault SystèmesDELMIA AprisoCritical
CVE-2025-620428/10/25Dassault SystèmesDELMIA AprisoHigh
CVE-2025-5423624/10/25AdobeCommerceCritical
CVE-2025-5928724/10/25MicrosoftWindows Server (WSUS)Critical
CVE-2025-6193222/10/25MOTEX Inc.Lanscope Endpoint ManagerCritical
CVE-2025-6188420/10/25Oracle CorporationOracle ConfiguratorHigh
CVE-2022-4850320/10/25ApplemacOSHigh
CVE-2025-274620/10/25KenticoXperienceCritical
CVE-2025-274720/10/25KenticoXperienceCritical
CVE-2025-3307320/10/25MicrosoftWindowsHigh
CVE-2025-5425315/10/25AdobeExperience ManagerCritical
CVE-2025-4782714/10/25IGELIGEL OSMedium
CVE-2025-626414/10/25Rapid7VelociraptorMedium
CVE-2016-783614/10/25Sky Co., LTD.SKYSEA Client ViewCritical
CVE-2025-5923014/10/25MicrosoftWindowsHigh
CVE-2025-2499014/10/25MicrosoftWindowsHigh
CVE-2021-4379809/10/25GrafanaGrafanaHigh
CVE-2025-2791507/10/25ZimbraCollaborationMedium
CVE-2010-396206/10/25MicrosoftInternet ExplorerHigh
CVE-2025-6188206/10/25Oracle CorporationOracle Concurrent Processing (EBS)Critical
CVE-2021-2255506/10/25Linux / NetAppLinux kernelHigh
CVE-2010-376506/10/25MozillaFirefoxCritical
CVE-2021-4322606/10/25MicrosoftWindowsHigh
CVE-2011-340206/10/25MicrosoftWindowsHigh
CVE-2013-391806/10/25MicrosoftWindowsHigh
CVE-2025-400802/10/25SmartbeddedMeteoBridgeCritical
CVE-2015-775502/10/25JuniperScreenOSCritical
CVE-2017-100035302/10/25JenkinsJenkinsCritical
CVE-2014-627802/10/25GNUBashCritical
CVE-2025-2104302/10/25Samsung MobileSamsung Mobile DevicesHigh

November 2025

CVE IDDate AddedVendorProductVLAI Severity
CVE-2025-4870304/11/25centos-webpanelCentOS Web PanelCritical
CVE-2025-1137104/11/25GladinetCentreStack / TrioFoxMedium
CVE-2025-2104210/11/25Samsung MobileSamsung Mobile DevicesHigh
CVE-2025-924212/11/25WatchGuardFireware OSCritical
CVE-2025-6221512/11/25MicrosoftWindowsHigh
CVE-2025-1248012/11/25TrioFoxTrioFoxCritical
CVE-2025-6444614/11/25FortinetFortiWebCritical
CVE-2025-5803418/11/25FortinetFortiWebHigh
CVE-2025-1322319/11/25GoogleChromeHigh
CVE-2025-6175721/11/25Oracle CorporationIdentity ManagerCritical
CVE-2021-2682928/11/25scadabrscadabrMedium

December 2025

CVE IDDate AddedVendorProductVLAI Severity
CVE-2025-1484729/12/25MongoDB Inc.MongoDB ServerHigh
CVE-2023-5216322/12/25DigiEverDS-2105 ProHigh
CVE-2025-1473319/12/25WatchGuardFireware OSCritical
CVE-2025-2039317/12/25CiscoCisco Secure EmailCritical
CVE-2025-4060217/12/25SonicWallSMA1000Medium
CVE-2025-5937417/12/25ASUSLive UpdateCritical
CVE-2025-5971816/12/25FortinetFortiSwitchManagerCritical
CVE-2025-4352915/12/25AppleiOS / iPadOSHigh
CVE-2025-1461115/12/25GladinetCentreStack / TrioFoxHigh
CVE-2025-1417412/12/25GoogleChromeHigh
CVE-2018-406312/12/25Sierra WirelessALEOSHigh
CVE-2025-5836011/12/25GeoServerGeoServerHigh
CVE-2025-6222109/12/25MicrosoftWindowsHigh
CVE-2025-621809/12/25RARLABWinRARHigh
CVE-2025-6664408/12/25Array NetworksArrayOS AGHigh
CVE-2022-3705508/12/25D-LinkGO-RT-AC750Critical
CVE-2025-5518205/12/25Metareact-server-dom-webpackCritical
CVE-2021-2682803/12/25scadabrscadabrHigh
CVE-2025-4863302/12/25GoogleAndroidHigh
CVE-2025-4857202/12/25GoogleAndroidHigh

EUVD / ENISA KEV

September 2025

CVE IDDate AddedVendorProductVLAI Severity
CVE-2025-2523109/09/25OmnissaWorkspace ONE UEMHigh

October, November, December 2025

No new entry was added to the EUVD / ENISA Known Exploited Vulnerabilities catalog during October, November and December 2025.

CIRCL KEV

The CIRCL Known Exploited Vulnerabilities catalog (catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd) tracks vulnerabilities that CIRCL has confirmed exploited based on its own incident-response, honeypot, and sinkhole telemetry. The entries below correspond to KEV records with confirmed exploitation activity observed during 2025:

CVE IDVendorProductFirst seenLast seenEvidence source
CVE-2023-28771ZyxelZyWALL/USG, USG FLEX, ATP, VPN, ZLD firmware2025-01-012026-01-28CIRCL sinkhole (cti-feed.circl.lu)
CVE-2025-53770MicrosoftSharePoint Server (“ToolShell”)2025-07-202025-09-30CIRCL incident response

The CIRCL KEV catalog remains intentionally small and high-confidence — every entry is backed by first-hand evidence collected by CIRCL — which is why its 2025 footprint is much narrower than the CISA KEV catalog.

Insights from Contributors

The following community comments and bundles were among the most relevant content shared on Vulnerability-Lookup during 2025.

January

February

March

April

May

June

July

August

September

October

November

December

Thank you

A heartfelt thank you to all the contributors, source maintainers, and users who reported sightings, posted comments, curated bundles, and provided feedback throughout 2025. Vulnerability-Lookup is a community effort, and the depth of this year-in-review is a direct reflection of your engagement. Special thanks to the Shadowserver Foundation, the MISP project, the CISA KEV, the EUVD / ENISA team, and the many researchers who share information openly with the community.

If you want to contribute to the next report, you can create your account.

Feedback and Support

If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us: https://github.com/vulnerability-lookup/vulnerability-lookup/issues/

You can also explore and reuse the AI tooling that produced this report: VulnMCPhttps://github.com/vulnerability-lookup/VulnMCP.

Funding

eu_funded_en

The main objective of the Federated European Team for Threat Analysis (FETTA) is the improvement of Cyber Threat Intelligence (CTI) products available to the public and private sectors in Poland, Luxembourg, and the European Union as a whole. Developing actionable CTI products (reports, indicators, etc.) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.

The Computer Incident Response Center Luxembourg (CIRCL) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organisation brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.

Press release