<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Lookup – News</title><link>http://www.vulnerability-lookup.org/news/</link><description>Recent content in News on Vulnerability-Lookup</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Wed, 03 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="http://www.vulnerability-lookup.org/news/index.xml" rel="self" type="application/rss+xml"/><item><title>Vulnerability Report - May 2026</title><link>http://www.vulnerability-lookup.org/2026/06/03/vulnerability-report-may-2026/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/06/03/vulnerability-report-may-2026/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated with the help of AI, using the
&lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;VulnMCP&lt;/a&gt; tooling on top of
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform&amp;rsquo;s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerabilities for May 2026, based on data
aggregated from &lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;, the
&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"target="_blank" rel="noopener"&gt;CISA Known Exploited Vulnerabilities&lt;/a&gt;
catalog, the &lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt; KEV catalog, the
&lt;a href="https://euvd.enisa.europa.eu/"target="_blank" rel="noopener"&gt;ENISA EUVD&lt;/a&gt; feed, and contributor comments and bundles.
Sightings come from &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky,
&lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/TeleGramSight"target="_blank" rel="noopener"&gt;Telegram&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;,
&lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, &lt;a href="https://github.com/rapid7/metasploit-framework"target="_blank" rel="noopener"&gt;Metasploit&lt;/a&gt;,
and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;May 2026 was, once again, the month of the Linux kernel &amp;ldquo;Copy Fail&amp;rdquo; flaw. &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-31431"target="_blank" rel="noopener"&gt;CVE-2026-31431&lt;/a&gt; (algif_aead in-place operation regression) more than doubled its activity, drawing &lt;strong&gt;574 sightings&lt;/strong&gt; &amp;ndash; up from 279 in April &amp;ndash; and remaining the most observed vulnerability on the platform by a wide margin. Two further Linux kernel networking flaws in the same family of &amp;ldquo;shared skb fragment&amp;rdquo; issues, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-43284"target="_blank" rel="noopener"&gt;CVE-2026-43284&lt;/a&gt; (xfrm/ESP) and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-43500"target="_blank" rel="noopener"&gt;CVE-2026-43500&lt;/a&gt; (rxrpc), also entered the top ranking, underlining sustained scrutiny of the kernel crypto and networking paths.&lt;/p&gt;
&lt;p&gt;Edge-security appliances dominated the exploited side of the month. Palo Alto Networks PAN-OS suffered two separate KEV-listed flaws: a critical unauthenticated buffer overflow in the User-ID Authentication Portal (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-0300"target="_blank" rel="noopener"&gt;CVE-2026-0300&lt;/a&gt;, CVSS 9.3) added to CISA KEV on May 6, and GlobalProtect authentication bypass &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-0257"target="_blank" rel="noopener"&gt;CVE-2026-0257&lt;/a&gt; added on May 29. Cisco&amp;rsquo;s Catalyst SD-WAN authentication bypass &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20182"target="_blank" rel="noopener"&gt;CVE-2026-20182&lt;/a&gt; (CVSS 10.0) prompted CISA Emergency Directive ED 26-03. WebPros &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-41940"target="_blank" rel="noopener"&gt;cPanel &amp;amp; WHM CVE-2026-41940&lt;/a&gt; carried over from April as the second-most-sighted issue (320 sightings) and was confirmed in ransomware campaigns by the ENISA / EU CSIRTs Network.&lt;/p&gt;
&lt;p&gt;A clear &lt;strong&gt;software supply-chain&lt;/strong&gt; theme emerged: CISA added three &amp;ldquo;embedded malicious code&amp;rdquo; entries within a single week &amp;ndash; TanStack (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-45321"target="_blank" rel="noopener"&gt;CVE-2026-45321&lt;/a&gt;), Nx Console (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-48027"target="_blank" rel="noopener"&gt;CVE-2026-48027&lt;/a&gt;, CWE-506) and Daemon Tools Lite (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-8398"target="_blank" rel="noopener"&gt;CVE-2026-8398&lt;/a&gt;) &amp;ndash; all involving trojanised packages or extensions used to harvest credentials.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;AI stack&lt;/strong&gt; continued to be a recurring exposure surface. CISA KEV-listed BerriAI &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-42208"target="_blank" rel="noopener"&gt;LiteLLM SQLi (CVE-2026-42208)&lt;/a&gt; and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-34291"target="_blank" rel="noopener"&gt;Langflow CVE-2025-34291&lt;/a&gt;, while contributors documented an unauthenticated memory-leak in Ollama (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-7482"target="_blank" rel="noopener"&gt;CVE-2026-7482&lt;/a&gt;, &amp;ldquo;Bleeding Llama&amp;rdquo;). NGINX heap overflow &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-42945"target="_blank" rel="noopener"&gt;CVE-2026-42945&lt;/a&gt; and a long tail of WordPress/Freemius reflected-XSS (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-13362"target="_blank" rel="noopener"&gt;CVE-2024-13362&lt;/a&gt;) rounded out the high-volume sightings.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; added &lt;strong&gt;21 entries&lt;/strong&gt; during May, spanning fresh edge-appliance and AI-stack RCEs, supply-chain malware, and a notable re-anchoring batch of legacy Microsoft and Adobe issues from 2008-2010 (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2008-4250"target="_blank" rel="noopener"&gt;CVE-2008-4250&lt;/a&gt; / MS08-067, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-0249"target="_blank" rel="noopener"&gt;CVE-2010-0249&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2009-3459"target="_blank" rel="noopener"&gt;CVE-2009-3459&lt;/a&gt;). The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;CIRCL KEV catalog&lt;/a&gt; added the Linux kernel &amp;ldquo;Copy Fail&amp;rdquo; flaw on the basis of incident-response host-log evidence, and the &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;ENISA EUVD KEV catalog&lt;/a&gt; surfaced three entries during May, including the cPanel &amp;amp; WHM authentication bypass flagged as ransomware-linked by CERT-PL.&lt;/p&gt;
&lt;p&gt;By CWE, the month was characterised by memory-corruption in the kernel and edge appliances (CWE-787, CWE-122), authentication bypass (CWE-565, CWE-287, CWE-306), SQL injection in AI/web tooling (CWE-89), cross-site scripting (CWE-79), and a distinct spike in embedded-malicious-code supply-chain entries (CWE-506).&lt;/p&gt;
&lt;h2&gt;Top 10 Vendors of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/06/top-10-vendors.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/06/top-10-vendors.png" alt="Top 10 Vendors of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 Assigners of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-assigners-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-assigners-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/06/top-10-assigners.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/06/top-10-assigners.png" alt="Top 10 Assigners of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-31431"target="_blank" rel="noopener"&gt;CVE-2026-31431&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;574&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Kernel (algif_aead)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9482)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-41940"target="_blank" rel="noopener"&gt;CVE-2026-41940&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;320&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WebPros"target="_blank" rel="noopener"&gt;WebPros&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WebPros&amp;amp;product=cPanel"target="_blank" rel="noopener"&gt;cPanel &amp;amp; WHM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8211)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-42945"target="_blank" rel="noopener"&gt;CVE-2026-42945&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;180&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=F5"target="_blank" rel="noopener"&gt;F5&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=F5&amp;amp;product=NGINX"target="_blank" rel="noopener"&gt;NGINX&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8166)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-43284"target="_blank" rel="noopener"&gt;CVE-2026-43284&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;174&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Kernel (xfrm/ESP)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9722)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-0300"target="_blank" rel="noopener"&gt;CVE-2026-0300&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;172&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks"target="_blank" rel="noopener"&gt;Palo Alto Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks&amp;amp;product=PAN-OS"target="_blank" rel="noopener"&gt;PAN-OS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9876)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-42897"target="_blank" rel="noopener"&gt;CVE-2026-42897&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;117&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Exchange&amp;#43;Server"target="_blank" rel="noopener"&gt;Exchange Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.4482)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-13362"target="_blank" rel="noopener"&gt;CVE-2024-13362&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;112&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Freemius"target="_blank" rel="noopener"&gt;Freemius&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Freemius"target="_blank" rel="noopener"&gt;Freemius SDK (WordPress)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9807)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-43500"target="_blank" rel="noopener"&gt;CVE-2026-43500&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;106&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Kernel (rxrpc)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.4832)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-0257"target="_blank" rel="noopener"&gt;CVE-2026-0257&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;95&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks"target="_blank" rel="noopener"&gt;Palo Alto Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks&amp;amp;product=PAN-OS"target="_blank" rel="noopener"&gt;PAN-OS (GlobalProtect)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.953)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20182"target="_blank" rel="noopener"&gt;CVE-2026-20182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;86&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN&amp;#43;Manager"target="_blank" rel="noopener"&gt;Catalyst SD-WAN Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.995)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;Exploited CVE ratio&lt;span class="hx:absolute hx:-mt-20" id="exploited-cve-ratio"&gt;&lt;/span&gt;
&lt;a href="#exploited-cve-ratio" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/06/exploited_CVE_ratio.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/06/exploited_CVE_ratio.png" alt="Exploited CVE ration" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-0257"target="_blank" rel="noopener"&gt;CVE-2026-0257&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-29&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks"target="_blank" rel="noopener"&gt;Palo Alto Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks&amp;amp;product=PAN-OS"target="_blank" rel="noopener"&gt;PAN-OS (GlobalProtect)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.953)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-45321"target="_blank" rel="noopener"&gt;CVE-2026-45321&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-27&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TanStack"target="_blank" rel="noopener"&gt;TanStack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TanStack&amp;amp;product=TanStack"target="_blank" rel="noopener"&gt;TanStack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8857)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-48027"target="_blank" rel="noopener"&gt;CVE-2026-48027&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-27&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Nx"target="_blank" rel="noopener"&gt;Nx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Nx&amp;amp;product=Nx&amp;#43;Console"target="_blank" rel="noopener"&gt;Nx Console&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.7056)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-8398"target="_blank" rel="noopener"&gt;CVE-2026-8398&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-27&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Daemon"target="_blank" rel="noopener"&gt;Daemon&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Daemon&amp;amp;product=Daemon&amp;#43;Tools&amp;#43;Lite"target="_blank" rel="noopener"&gt;Daemon Tools Lite&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5318)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-48172"target="_blank" rel="noopener"&gt;CVE-2026-48172&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=LiteSpeed"target="_blank" rel="noopener"&gt;LiteSpeed&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=LiteSpeed&amp;amp;product=cPanel&amp;#43;Plugin"target="_blank" rel="noopener"&gt;cPanel Plugin&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7521)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-9082"target="_blank" rel="noopener"&gt;CVE-2026-9082&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-22&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Drupal"target="_blank" rel="noopener"&gt;Drupal&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Drupal&amp;amp;product=Drupal&amp;#43;core"target="_blank" rel="noopener"&gt;Core&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.621)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34926"target="_blank" rel="noopener"&gt;CVE-2026-34926&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-21&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Trend&amp;#43;Micro"target="_blank" rel="noopener"&gt;Trend Micro&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Trend&amp;#43;Micro&amp;amp;product=Apex&amp;#43;One"target="_blank" rel="noopener"&gt;Apex One&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9918)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-34291"target="_blank" rel="noopener"&gt;CVE-2025-34291&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-21&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Langflow"target="_blank" rel="noopener"&gt;Langflow&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Langflow&amp;amp;product=Langflow"target="_blank" rel="noopener"&gt;Langflow&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.987)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-41091"target="_blank" rel="noopener"&gt;CVE-2026-41091&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Defender"target="_blank" rel="noopener"&gt;Defender&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9057)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-45498"target="_blank" rel="noopener"&gt;CVE-2026-45498&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Defender"target="_blank" rel="noopener"&gt;Defender&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9434)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2008-4250"target="_blank" rel="noopener"&gt;CVE-2008-4250&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows"target="_blank" rel="noopener"&gt;Windows (Server Service)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.795)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2009-3459"target="_blank" rel="noopener"&gt;CVE-2009-3459&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Adobe&amp;#43;Acrobat&amp;#43;and&amp;#43;Reader"target="_blank" rel="noopener"&gt;Acrobat and Reader&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8861)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-0249"target="_blank" rel="noopener"&gt;CVE-2010-0249&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Internet&amp;#43;Explorer"target="_blank" rel="noopener"&gt;Internet Explorer&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7062)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-0806"target="_blank" rel="noopener"&gt;CVE-2010-0806&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Internet&amp;#43;Explorer"target="_blank" rel="noopener"&gt;Internet Explorer&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.7167)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2009-1537"target="_blank" rel="noopener"&gt;CVE-2009-1537&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=DirectX"target="_blank" rel="noopener"&gt;DirectX&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.4378)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-42897"target="_blank" rel="noopener"&gt;CVE-2026-42897&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-15&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Exchange&amp;#43;Server"target="_blank" rel="noopener"&gt;Exchange Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.4482)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20182"target="_blank" rel="noopener"&gt;CVE-2026-20182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-14&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN&amp;#43;Manager"target="_blank" rel="noopener"&gt;Catalyst SD-WAN Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.995)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-42208"target="_blank" rel="noopener"&gt;CVE-2026-42208&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-08&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=BerriAI"target="_blank" rel="noopener"&gt;BerriAI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=BerriAI&amp;amp;product=LiteLLM"target="_blank" rel="noopener"&gt;LiteLLM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.851)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-6973"target="_blank" rel="noopener"&gt;CVE-2026-6973&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-07&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint&amp;#43;Manager&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile (EPMM)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9765)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-0300"target="_blank" rel="noopener"&gt;CVE-2026-0300&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-06&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks"target="_blank" rel="noopener"&gt;Palo Alto Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Palo&amp;#43;Alto&amp;#43;Networks&amp;amp;product=PAN-OS"target="_blank" rel="noopener"&gt;PAN-OS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9876)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-31431"target="_blank" rel="noopener"&gt;CVE-2026-31431&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-01&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Kernel (algif_aead)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9482)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CISA Catalog.&lt;/p&gt;
&lt;h3&gt;CIRCL&lt;span class="hx:absolute hx:-mt-20" id="circl"&gt;&lt;/span&gt;
&lt;a href="#circl" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-31431"target="_blank" rel="noopener"&gt;CVE-2026-31431&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-04&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Kernel (algif_aead)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9482)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Added on the basis of incident-response host logs (&amp;ldquo;seen exploited on a system giving shell access to users&amp;rdquo;), confirming local privilege escalation in the wild.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CIRCL Catalog.&lt;/p&gt;
&lt;h3&gt;ENISA (EUVD)&lt;span class="hx:absolute hx:-mt-20" id="enisa-euvd"&gt;&lt;/span&gt;
&lt;a href="#enisa-euvd" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The following entries from the ENISA / EU CSIRTs Network (CNW) KEV feed were surfaced in Vulnerability-Lookup during May. The cPanel &amp;amp; WHM authentication bypass is flagged as ransomware-linked by CERT-PL; the Roundcube XSS is attributed to APT activity (UNC1151).&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Date Reported&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-41940"target="_blank" rel="noopener"&gt;CVE-2026-41940&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-05-08&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WebPros"target="_blank" rel="noopener"&gt;WebPros&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WebPros&amp;amp;product=cPanel"target="_blank" rel="noopener"&gt;cPanel &amp;amp; WHM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8211)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-42009"target="_blank" rel="noopener"&gt;CVE-2024-42009&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-27&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube"target="_blank" rel="noopener"&gt;Roundcube&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube&amp;amp;product=Webmail"target="_blank" rel="noopener"&gt;Webmail&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9215)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20963"target="_blank" rel="noopener"&gt;CVE-2026-20963&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=SharePoint"target="_blank" rel="noopener"&gt;SharePoint&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9949)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the ENISA Catalog.&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2026&amp;amp;month=05"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/06/top-10-weaknesses.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Community contributions in May combined hands-on mitigation guidance for the &amp;ldquo;Copy Fail&amp;rdquo; kernel flaw with deep-dive analysis of emerging AI-stack risks.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/5e9c3f17-4570-484f-9113-fab5ca85b815"target="_blank" rel="noopener"&gt;Deny alg_socket to Containers with SELinux to Mitigate CVE-2026-31431&lt;/a&gt; &amp;ndash; a detailed, tested walk-through of an SELinux deny rule (&lt;code&gt;alg_socket&lt;/code&gt;) for container runtimes, plus &lt;code&gt;RestrictAddressFamilies=~AF_ALG&lt;/code&gt; / &lt;code&gt;SystemCallArchitectures=native&lt;/code&gt; per-service hardening and Red Hat&amp;rsquo;s &lt;code&gt;initcall_blacklist&lt;/code&gt; boot-argument approach. The recurring theme: AF_ALG / &lt;code&gt;algif_aead&lt;/code&gt; is rarely needed by user workloads, so denying it at the container or systemd-unit boundary is a pragmatic mitigation.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/f6d41719-7e76-40c7-ac12-d7d70f2ac1db"target="_blank" rel="noopener"&gt;Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026-7482)&lt;/a&gt; &amp;ndash; a shared write-up of Cyera Research&amp;rsquo;s analysis of an out-of-bounds heap read in Ollama&amp;rsquo;s GGUF quantization path (&lt;code&gt;/api/create&lt;/code&gt;), exfiltratable via &lt;code&gt;/api/push&lt;/code&gt; to an attacker-controlled URI. With ~300,000 Ollama servers exposed (listening on &lt;code&gt;0.0.0.0&lt;/code&gt; with no authentication by default), three unauthenticated API calls can leak user prompts, system prompts, and host environment variables.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/5891d215-6f38-4734-8904-101fe25c4e26"target="_blank" rel="noopener"&gt;CVE-2026-0300 PAN-OS Authentication Portal buffer overflow&lt;/a&gt; &amp;ndash; a pointer to the Palo Alto Networks advisory for the critical unauthenticated User-ID Authentication Portal overflow.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Contributors also curated a number of vendor advisories into bundles during May, helping group related fixes for triage:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/0dbba751-347d-454d-a712-20656debd033"target="_blank" rel="noopener"&gt;Unauthenticated Remote Code Execution in Samba printing subsystem&lt;/a&gt; and the corresponding &lt;a href="https://vulnerability.circl.lu/bundle/ef598036-eda2-4311-807e-ebbdfb04a51d"target="_blank" rel="noopener"&gt;Debian DSA 6297-1 samba security update&lt;/a&gt; (6 CVEs).&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/19afabe0-44dd-4520-bb1b-4359ad0d9b15"target="_blank" rel="noopener"&gt;Security content of iOS / iPadOS 26.5&lt;/a&gt; (61 CVEs) and &lt;a href="https://vulnerability.circl.lu/bundle/43ea14c5-971c-4e1b-a785-7436e620bd49"target="_blank" rel="noopener"&gt;macOS Tahoe 26.5&lt;/a&gt; (79 CVEs).&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/98dfc241-f74a-4ad3-9b5d-a312ab6e6c87"target="_blank" rel="noopener"&gt;rsync 3.4.3&lt;/a&gt; (7 CVEs), &lt;a href="https://vulnerability.circl.lu/bundle/bb20f34e-4314-42f2-8e6b-cb2c917339bc"target="_blank" rel="noopener"&gt;dnsmasq May 2026 advisory&lt;/a&gt; (6 CVEs), &lt;a href="https://vulnerability.circl.lu/bundle/eed1dbdf-5a0f-4cc2-9665-fa1ff05b0c1f"target="_blank" rel="noopener"&gt;Firefox 150.0.3 / MFSA 2026-45&lt;/a&gt; (5 CVEs), &lt;a href="https://vulnerability.circl.lu/bundle/20100033-b137-47a0-b98c-568c18deda5a"target="_blank" rel="noopener"&gt;Moodle May 2026&lt;/a&gt; (7 CVEs), &lt;a href="https://vulnerability.circl.lu/bundle/1f150b5f-d6d1-40b6-94cc-7bd855a097ec"target="_blank" rel="noopener"&gt;Exim 4.99.2&lt;/a&gt; (4 CVEs), and &lt;a href="https://vulnerability.circl.lu/bundle/63ae1405-3878-4622-935b-6ee96a75dc90"target="_blank" rel="noopener"&gt;ImageMagick DSA 6240-1&lt;/a&gt; (15 CVEs).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL&amp;rsquo;s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 5.0.0 released</title><link>http://www.vulnerability-lookup.org/2026/05/29/vulnerability-lookup-5-0-0/</link><pubDate>Fri, 29 May 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/05/29/vulnerability-lookup-5-0-0/</guid><description>
&lt;p&gt;We are thrilled to announce the release of &lt;strong&gt;Vulnerability-Lookup 5.0.0&lt;/strong&gt;!&lt;/p&gt;
&lt;p&gt;This major release centers on a new &lt;strong&gt;CNA-interoperable API&lt;/strong&gt; for managing the vulnerabilities of your local source, together with deep Vulnogram integration, a continued UI refresh, and a long list of stability and correctness fixes.&lt;/p&gt;
&lt;p&gt;A special thank you to &lt;a href="https://github.com/NMD03"target="_blank" rel="noopener"&gt;Niclas Dauster&lt;/a&gt; for the substantial contribution behind the new CNA-interoperable API (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/398"target="_blank" rel="noopener"&gt;#398&lt;/a&gt;).&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;CNA- and GNA-Compatible Vulnerability Management&lt;span class="hx:absolute hx:-mt-20" id="cna--and-gna-compatible-vulnerability-management"&gt;&lt;/span&gt;
&lt;a href="#cna--and-gna-compatible-vulnerability-management" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Vulnerabilities in your local instance can now be managed in a &lt;strong&gt;CNA-interoperable&lt;/strong&gt; way through a &lt;a href="https://vulnerability.circl.lu/api/#operations-tag-cna"target="_blank" rel="noopener"&gt;dedicated API&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;It streamlines Coordinated Vulnerability Disclosure (CVD) through a built-in Vulnogram integration compatible with both &lt;a href="https://github.com/CVEProject/cve-schema/blob/main/README.md"target="_blank" rel="noopener"&gt;CVE 5.2&lt;/a&gt; and &lt;a href="https://gcve.eu/bcp/gcve-bcp-05/"target="_blank" rel="noopener"&gt;GCVE-BCP-05&lt;/a&gt;, allowing CNAs and GNAs to publish advisories and &lt;a href="https://gcve.eu/bcp/gcve-bcp-03/"target="_blank" rel="noopener"&gt;synchronize with other instances&lt;/a&gt; regardless of the identifier format used.&lt;/p&gt;
&lt;p&gt;The new API endpoint is partially interoperable with existing CNA endpoints from the CVE program, building on its solid foundation to enable a compatible and unified system for publishing vulnerability information. The API may be refined in upcoming releases based on feedback from adopters. We firmly believe that interoperable, reusable open-source components are key to preventing fragmentation in the vulnerability ecosystem.&lt;/p&gt;
&lt;p&gt;We also welcome other vulnerability publication programs to extend this API to support their specific use cases or new models that could further improve automation in vulnerability handling.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-CNA-Compliant-API.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-CNA-Compliant-API.png" alt="Vulnerability-Lookup 5.0.0 CNA-compliant API overview" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Vulnogram integration&lt;span class="hx:absolute hx:-mt-20" id="vulnogram-integration"&gt;&lt;/span&gt;
&lt;a href="#vulnogram-integration" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Vulnogram now drives ID reservation within vulnerability-lookup directly and vulnerability data management directly through the new CNA-interoperable API:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;a dialog to view and reserve identifiers,&lt;/li&gt;
&lt;li&gt;range-document creation,&lt;/li&gt;
&lt;li&gt;state filtering,&lt;/li&gt;
&lt;li&gt;reject and delete actions,&lt;/li&gt;
&lt;li&gt;reserved IDs inserted directly into the form.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-Reserved-IDs.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-Reserved-IDs.png" alt="Vulnerability-Lookup 5.0.0 reserved IDs dialog" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-New-ID-Reservation.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-New-ID-Reservation.png" alt="Vulnerability-Lookup 5.0.0 new ID reservation form" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-Edit-GCVE.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-Edit-GCVE.png" alt="Vulnerability-Lookup 5.0.0 edit GCVE entry interface" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Configurable identifier allocation&lt;span class="hx:absolute hx:-mt-20" id="configurable-identifier-allocation"&gt;&lt;/span&gt;
&lt;a href="#configurable-identifier-allocation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;You can now configure GCVE identifier allocation ranges for reservation. A &lt;code&gt;bin&lt;/code&gt; script is also provided to migrate existing data to the new GNA ID format.&lt;/p&gt;
&lt;h3&gt;Website improvements&lt;span class="hx:absolute hx:-mt-20" id="website-improvements"&gt;&lt;/span&gt;
&lt;a href="#website-improvements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;A new &lt;code&gt;/kev-catalogs&lt;/code&gt; view listing all &lt;a href="https://gcve.eu/bcp/gcve-bcp-07/"target="_blank" rel="noopener"&gt;KEV catalogs&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Recent sightings are now rendered inside a dedicated home page tab.&lt;/li&gt;
&lt;li&gt;Related vulnerabilities on the CWE detail page are now paginated (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/406"target="_blank" rel="noopener"&gt;#406&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;API&lt;span class="hx:absolute hx:-mt-20" id="api"&gt;&lt;/span&gt;
&lt;a href="#api" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;IPs/CIDRs can now be allowlisted to exempt them from the &lt;code&gt;/api&lt;/code&gt; read rate limits.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;UI refresh&lt;/strong&gt; — We introduced a shared card design language (rounded cards, soft hover, brand-tinted leading icon badges) and applied it across the About, home, &lt;code&gt;/recent&lt;/code&gt; and vulnerability pages. The About page gains a hero banner, feature highlights and live stats; the source dropdown on the recent vulnerabilities page was improved; popover triggers on vulnerability views were harmonized; and the sightings correlations tabs were reorganized. More UI improvements will come in future releases.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Production reference architecture&lt;/strong&gt; — The documentation now includes a &lt;a href="https://www.vulnerability-lookup.org/documentation/performance-tuning.html"target="_blank" rel="noopener"&gt;production reference architecture&lt;/a&gt; (HAProxy, Varnish, CDN, dumps and configuration examples).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-Vulnerability-View.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/Vulnerability-Lookup-5.0.0-Vulnerability-View.png" alt="Refreshed Vulnerability View" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;It also addresses a number of other issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;UI&lt;/strong&gt; — Preserve the VLAI popover header when refreshing content; align right-side navbar dropdowns to prevent overflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Website&lt;/strong&gt; — Make Choices.js search inputs readable in the dark theme; repopulate the product list when the vendor changes on the search page; propagate config &lt;code&gt;DEBUG=True&lt;/code&gt; to the &lt;code&gt;FLASK_DEBUG&lt;/code&gt; environment variable.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Core&lt;/strong&gt; — Add a timeout to graceful shutdown to prevent an infinite loop (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/409"target="_blank" rel="noopener"&gt;#409&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;API&lt;/strong&gt; — Correct the &lt;code&gt;per_page&lt;/code&gt; range check across the remaining endpoints, including rulezet and user (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/411"target="_blank" rel="noopener"&gt;#411&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Docker&lt;/strong&gt; — Use the kvrocks container name in &lt;code&gt;.env.sample&lt;/code&gt; (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/407"target="_blank" rel="noopener"&gt;#407&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Typing&lt;/strong&gt; — Assorted mypy/typing fixes and Python 3.11 f-string compatibility.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Migration Notes&lt;span class="hx:absolute hx:-mt-20" id="migration-notes"&gt;&lt;/span&gt;
&lt;a href="#migration-notes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A &lt;code&gt;bin&lt;/code&gt; script is provided to migrate existing local-source data to the new GNA ID format.&lt;/p&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v5.0.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v5.0.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 A big thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real-time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 4.6.0 released</title><link>http://www.vulnerability-lookup.org/2026/05/21/vulnerability-lookup-4-6-0/</link><pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/05/21/vulnerability-lookup-4-6-0/</guid><description>
&lt;p&gt;We are excited to announce the release of &lt;strong&gt;Vulnerability-Lookup 4.6.0&lt;/strong&gt;!&lt;br&gt;
This version brings more transparency, new data sources, API improvements, notable UI enhancements, and several performance and stability fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;VLAI model transparency&lt;span class="hx:absolute hx:-mt-20" id="vlai-model-transparency"&gt;&lt;/span&gt;
&lt;a href="#vlai-model-transparency" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI&lt;/a&gt; badge popover now surfaces the exact model name and revision used for a given analysis, with direct links to the HuggingFace model card and the revision commit. This is particularly useful as we regularly update our AI models and publish new versions on &lt;a href="https://huggingface.co/CIRCL"target="_blank" rel="noopener"&gt;HuggingFace&lt;/a&gt;, making it easy to track exactly which model version produced a given result.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/VLAI_version1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/VLAI_version1.png" alt="VLAI badge popover showing the AI model name and exact revision commit used for severity classification of a CVE" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/VLAI_version2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/VLAI_version2.png" alt="VLAI badge popover on a Chinese-language advisory, showing the MacBERT-based model name, revision hash, and a link to the HuggingFace model card" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Moksha feeder&lt;span class="hx:absolute hx:-mt-20" id="moksha-feeder"&gt;&lt;/span&gt;
&lt;a href="#moksha-feeder" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;A new feeder for &lt;a href="https://moksha.circl.lu/"target="_blank" rel="noopener"&gt;Moksha&lt;/a&gt; has been added, mirroring the indexing pattern used by the cvelistv5 source. Because Moksha is accessible over Tor, the feeder requires a local Tor instance and is disabled by default.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/Moksha.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/Moksha.png" alt="Recent vulnerabilities page filtered to the Moksha source, listing MOKSHA-2026 entries for XenServer (Cloud Software Group) with CVSS scores, short descriptions, and publication dates" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;KEV catalog on the homepage and search results&lt;span class="hx:absolute hx:-mt-20" id="kev-catalog-on-the-homepage-and-search-results"&gt;&lt;/span&gt;
&lt;a href="#kev-catalog-on-the-homepage-and-search-results" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The latest entries from CISA&amp;rsquo;s Known Exploited Vulnerabilities (KEV) catalog are now displayed directly on the homepage. KEV catalog badges also appear on the search results page, giving you an immediate signal when a vulnerability is actively exploited in the wild.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/Home_page.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/Home_page.png" alt="Vulnerability-Lookup homepage showing four weekly sighting observation charts (mentions, confirmations, exploitations, published proof-of-concept), a recent activity sidebar, and the new Latest KEV Entries panel listing recently added CVEs" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Improved CSAF advisory display&lt;span class="hx:absolute hx:-mt-20" id="improved-csaf-advisory-display"&gt;&lt;/span&gt;
&lt;a href="#improved-csaf-advisory-display" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;CSAF advisories now show a structured per-status product table derived from the &lt;code&gt;product_tree&lt;/code&gt;, and the &lt;code&gt;/recent&lt;/code&gt; page loads only the selected source with its own pagination — making it faster to browse recent activity.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/CSAF.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/CSAF.png" alt="CSAF advisory detail page for WID-SEC-W-2026-1047 (Adobe Acrobat Reader), showing the new per-status Affected Products section with Known Affected and Last Affected groups, each listing product, identifier, version, and remediation columns" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;API additions&lt;span class="hx:absolute hx:-mt-20" id="api-additions"&gt;&lt;/span&gt;
&lt;a href="#api-additions" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;A new &lt;code&gt;with_meta&lt;/code&gt; parameter on the vulnerabilities list endpoint lets consumers fetch enriched metadata in a single call.&lt;/li&gt;
&lt;li&gt;Optional, tier-aware rate limits can now be applied to vulnerability read endpoints.&lt;/li&gt;
&lt;li&gt;A machine-readable access policy endpoint is available for automated consumers.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/API_policy.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/API_policy.png" alt="About page showing the new For Automated Consumers section, listing machine-readable access endpoints: api-policy.json, llms.txt, robots.txt, and security.txt" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Performance improvements&lt;/strong&gt; — Hot read endpoints are now cached with a Redis backend, full-text index writes are batched, and homepage sighting statistics are computed via a dedicated aggregated endpoint. These changes significantly reduce load under traffic spikes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Homepage and template updates&lt;/strong&gt; — The home page displays more information at a glance; the sources list on the About page is now in a collapsible accordion; Moksha is available in the &lt;code&gt;/recent&lt;/code&gt; source menu.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ML-Gateway&lt;/strong&gt; — The gateway response now includes the model name and revision, which are forwarded by the API (&lt;a href="https://github.com/vulnerability-lookup/ML-Gateway"target="_blank" rel="noopener"&gt;project page&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dependencies&lt;/strong&gt; — Python dependencies have been updated.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This release includes a number of stability and correctness fixes: rate-limiter accuracy improvements (correct client IP resolution, dedicated Redis backend), Flask-Caching Redis pool reliability under gunicorn/gevent, EPSS badges on search results, timezone-aware timestamps for comments and bundles, restricted comment editing to authorized users only, and several minor UI and template corrections.&lt;/p&gt;
&lt;h2&gt;Migration Notes&lt;span class="hx:absolute hx:-mt-20" id="migration-notes"&gt;&lt;/span&gt;
&lt;a href="#migration-notes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/de3deb93546e14cd30d06a19cc9dcf8efef0e61f"target="_blank" rel="noopener"&gt;Commit de3deb9&lt;/a&gt; adds a composite index &lt;code&gt;ix_sighting_creation_timestamp_type_vulnerability&lt;/code&gt; on the sighting table to support the &lt;code&gt;/api/sighting/stats&lt;/code&gt; aggregation as an index-only scan.&lt;/p&gt;
&lt;p&gt;To pick up the new index after pulling, run:&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;pre&gt;&lt;code&gt;poetry run flask --app website.app db upgrade&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Large instances:&lt;/strong&gt; On really large sighting tables, consider building the index with &lt;code&gt;CREATE INDEX CONCURRENTLY&lt;/code&gt; outside Alembic to avoid blocking writes during the build.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.6.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.6.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 A big thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt; I want
We appreciate your feedback!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report for the year 2025</title><link>http://www.vulnerability-lookup.org/2026/05/11/vulnerability-report-2025/</link><pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/05/11/vulnerability-report-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;div class="hx:overflow-x-auto hx:mt-6 hx:flex hx:rounded-lg hx:border hx:py-2 hx:ltr:pr-4 hx:rtl:pl-4 hx:contrast-more:border-current hx:contrast-more:dark:border-current hx:border-blue-200 hx:bg-blue-100 hx:text-blue-900 hx:dark:border-blue-200/30 hx:dark:bg-blue-900/30 hx:dark:text-blue-200"&gt;
&lt;div class="hx:ltr:pl-3 hx:ltr:pr-2 hx:rtl:pr-3 hx:rtl:pl-2"&gt;&lt;svg height=1.2em class="hx:inline-block hx:align-middle" xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M13 16h-1v-4h-1m1-4h.01M21 12a9 9 0 11-18 0 9 9 0 0118 0z"/&gt;&lt;/svg&gt;&lt;/div&gt;
&lt;div class="hx:w-full hx:min-w-0 hx:leading-7"&gt;
&lt;div class="hx:mt-6 hx:leading-7 hx:first:mt-0"&gt;This report was generated with the help of AI, leveraging the
&lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;VulnMCP&lt;/a&gt; Model Context
Protocol server connected to Vulnerability-Lookup. The underlying data was
aggregated from the twelve monthly reports published throughout 2025 and from
the live Vulnerability-Lookup API.&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hx:overflow-x-auto hx:mt-6 hx:flex hx:rounded-lg hx:border hx:py-2 hx:ltr:pr-4 hx:rtl:pl-4 hx:contrast-more:border-current hx:contrast-more:dark:border-current hx:border-blue-200 hx:bg-blue-100 hx:text-blue-900 hx:dark:border-blue-200/30 hx:dark:bg-blue-900/30 hx:dark:text-blue-200"&gt;
&lt;div class="hx:ltr:pl-3 hx:ltr:pr-2 hx:rtl:pr-3 hx:rtl:pl-2"&gt;&lt;svg height=1.2em class="hx:inline-block hx:align-middle" xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M13 16h-1v-4h-1m1-4h.01M21 12a9 9 0 11-18 0 9 9 0 0118 0z"/&gt;&lt;/svg&gt;&lt;/div&gt;
&lt;div class="hx:w-full hx:min-w-0 hx:leading-7"&gt;
&lt;div class="hx:mt-6 hx:leading-7 hx:first:mt-0"&gt;Download this report as a &lt;a href="http://www.vulnerability-lookup.org/files/news/2026/05/vulnerability-report-2025.pdf"&gt;PDF&lt;/a&gt;.&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The 2025 threat landscape was characterised by sustained pressure on
enterprise infrastructure, edge devices, and developer tooling. Attackers
continued to weaponise newly disclosed vulnerabilities within hours of
publication, while a long tail of unpatched &lt;strong&gt;legacy IoT and edge devices&lt;/strong&gt;
(D-Link, Zyxel, DASAN, Huawei, Realtek, Netgear) kept generating massive
exploitation noise. Several flagship incidents shaped the year: the
&lt;strong&gt;SAP NetWeaver Visual Composer&lt;/strong&gt; zero-day exploitation in April, the
&lt;strong&gt;SharePoint &amp;ldquo;ToolShell&amp;rdquo;&lt;/strong&gt; campaign in July, the &lt;strong&gt;NetScaler &amp;ldquo;CitrixBleed 2&amp;rdquo;&lt;/strong&gt;
saga from June onward, the &lt;strong&gt;Oracle E-Business Suite&lt;/strong&gt; exploitation tied to
the Cl0p activity in October, the &lt;strong&gt;WSUS critical&lt;/strong&gt; (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;)
in October-November, the &lt;strong&gt;FortiWeb&lt;/strong&gt; authentication bypasses in November,
and the dramatic &lt;strong&gt;React Server Components (&amp;ldquo;React2Shell&amp;rdquo;)&lt;/strong&gt; surge in
December.&lt;/p&gt;
&lt;p&gt;This year-in-review consolidates the twelve monthly reports covering 2025
and aggregates the data collected by
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;.
Sources used to build this report include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;&lt;/strong&gt; sightings&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;CISA KEV&lt;/a&gt;&lt;/strong&gt;
catalog&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;&lt;/strong&gt; team curation and security advisories&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;EUVD / ENISA&lt;/a&gt;&lt;/strong&gt; Known Exploited
Vulnerabilities catalog&lt;/li&gt;
&lt;li&gt;Community contributors via comments and bundles on the platform&lt;/li&gt;
&lt;li&gt;Sighting feeds: MISP, Exploit-DB, Bluesky, Mastodon, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt; honeypots,
&lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, Metasploit, &lt;a href="https://github.com/vulnerability-lookup/TeleGramSight"target="_blank" rel="noopener"&gt;Telegram&lt;/a&gt;, and &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/#automation-tools"target="_blank" rel="noopener"&gt;more&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This report was generated with AI assistance via &lt;strong&gt;VulnMCP&lt;/strong&gt;, the Model
Context Protocol server that exposes Vulnerability-Lookup capabilities to
AI agents: &lt;strong&gt;&lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/VulnMCP&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;h2&gt;The Year at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-year-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-year-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The charts below summarise publication trends and the ecosystem most affected
throughout 2025.&lt;/p&gt;
&lt;h3&gt;Evolution of CVE publication&lt;span class="hx:absolute hx:-mt-20" id="evolution-of-cve-publication"&gt;&lt;/span&gt;
&lt;a href="#evolution-of-cve-publication" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/evolution-CVE-published-2025.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/evolution-CVE-published-2025.png" alt="Evolution of CVE publications in 2025" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Top 10 CVE Assigners of the Year&lt;span class="hx:absolute hx:-mt-20" id="top-10-cve-assigners-of-the-year"&gt;&lt;/span&gt;
&lt;a href="#top-10-cve-assigners-of-the-year" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/top-10-assigners-2025.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/top-10-assigners-2025.png" alt="Top 10 CVE assigners in 2025" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Top 10 Weaknesses (CWE) of the Year&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-cwe-of-the-year"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-cwe-of-the-year" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/top-10-CWE-2025.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/top-10-CWE-2025.png" alt="Top 10 weaknesses (CWE) observed in 2025" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Top 10 Vendors in 2025&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-in-2025"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-in-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/05/top-10-vendors-2025.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/05/top-10-vendors-2025.png" alt="Top 10 vendors by sightings in 2025" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Recurring themes&lt;span class="hx:absolute hx:-mt-20" id="recurring-themes"&gt;&lt;/span&gt;
&lt;a href="#recurring-themes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;2025 delivered an unusually high volume of &lt;em&gt;actively exploited&lt;/em&gt;
vulnerabilities. Recurring themes across the year include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Edge &amp;amp; network devices&lt;/strong&gt; dominated continuous exploitation:
D-Link DIR-645 (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;),
Zyxel P660HN (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;),
DASAN GPON (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;),
Huawei HG532 (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt;)
remained in the top sightings &lt;em&gt;every single month&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;VPN / remote access&lt;/strong&gt;: Ivanti Connect Secure
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0282"target="_blank" rel="noopener"&gt;CVE-2025-0282&lt;/a&gt;,
&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22457"target="_blank" rel="noopener"&gt;CVE-2025-22457&lt;/a&gt;),
NetScaler ADC (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;,
&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6543"target="_blank" rel="noopener"&gt;CVE-2025-6543&lt;/a&gt;),
Fortinet FortiOS / FortiWeb / FortiSwitchManager, Palo Alto PAN-OS
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0108"target="_blank" rel="noopener"&gt;CVE-2025-0108&lt;/a&gt;),
SonicWall SMA, Check Point Quantum.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enterprise platforms&lt;/strong&gt;: SAP NetWeaver
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;),
Microsoft SharePoint (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770"target="_blank" rel="noopener"&gt;CVE-2025-53770&lt;/a&gt;),
Microsoft Exchange (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53786"target="_blank" rel="noopener"&gt;CVE-2025-53786&lt;/a&gt;),
Microsoft WSUS (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;),
Oracle E-Business Suite (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61882"target="_blank" rel="noopener"&gt;CVE-2025-61882&lt;/a&gt;),
Oracle Identity Manager (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61757"target="_blank" rel="noopener"&gt;CVE-2025-61757&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Developer ecosystem &amp;amp; supply chain&lt;/strong&gt;: Next.js middleware bypass
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29927"target="_blank" rel="noopener"&gt;CVE-2025-29927&lt;/a&gt;),
Apache Tomcat (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;),
Erlang/OTP SSH (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32433"target="_blank" rel="noopener"&gt;CVE-2025-32433&lt;/a&gt;),
&lt;code&gt;tj-actions/changed-files&lt;/code&gt; GitHub Action compromise
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30066"target="_blank" rel="noopener"&gt;CVE-2025-30066&lt;/a&gt;),
React Server Components &amp;ldquo;React2Shell&amp;rdquo;
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;),
npm &lt;code&gt;qix&lt;/code&gt;/&lt;code&gt;duckdb_admin&lt;/code&gt; account compromise.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Client-side&lt;/strong&gt;: Apple iOS/iPadOS/visionOS, Google Chrome V8, WinRAR
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8088"target="_blank" rel="noopener"&gt;CVE-2025-8088&lt;/a&gt;,
&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6218"target="_blank" rel="noopener"&gt;CVE-2025-6218&lt;/a&gt;),
7-Zip (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11001"target="_blank" rel="noopener"&gt;CVE-2025-11001&lt;/a&gt;),
Samsung Mobile zero-days
(&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21042"target="_blank" rel="noopener"&gt;CVE-2025-21042&lt;/a&gt;,
&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21043"target="_blank" rel="noopener"&gt;CVE-2025-21043&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CWE landscape&lt;/strong&gt;: Cross-site scripting (CWE-79) and SQL injection
(CWE-89) consistently topped the weakness charts, followed by
injection (CWE-74), code injection (CWE-94), and memory safety
issues (CWE-119/121/122/125/416).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In total, our community recorded &lt;strong&gt;tens of thousands of sightings&lt;/strong&gt; in 2025,
with hundreds of patches released, dozens of public proofs of concept, and
numerous in-the-wild exploitations confirmed by The Shadowserver Foundation
honeypot network, CISA KEV additions, and contributor reports.&lt;/p&gt;
&lt;h2&gt;Top 50 Vulnerabilities of the Year&lt;span class="hx:absolute hx:-mt-20" id="top-50-vulnerabilities-of-the-year"&gt;&lt;/span&gt;
&lt;a href="#top-50-vulnerabilities-of-the-year" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Most-sighted vulnerabilities recorded by Vulnerability-Lookup between
&lt;strong&gt;2025-01-01&lt;/strong&gt; and &lt;strong&gt;2025-12-31&lt;/strong&gt;. Severities are derived from the
&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI&lt;/a&gt; classifier.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1138&lt;/td&gt;
&lt;td&gt;Meta&lt;/td&gt;
&lt;td&gt;react-server-dom-webpack&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;726&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;710&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;671&lt;/td&gt;
&lt;td&gt;NetScaler&lt;/td&gt;
&lt;td&gt;ADC&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;627&lt;/td&gt;
&lt;td&gt;DASAN Networks&lt;/td&gt;
&lt;td&gt;GPON Router&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770"target="_blank" rel="noopener"&gt;CVE-2025-53770&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;619&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;SharePoint Enterprise Server 2016&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;566&lt;/td&gt;
&lt;td&gt;SAP&lt;/td&gt;
&lt;td&gt;SAP NetWeaver (Visual Composer)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-14774"target="_blank" rel="noopener"&gt;CVE-2018-14774&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;542&lt;/td&gt;
&lt;td&gt;Symfony&lt;/td&gt;
&lt;td&gt;HttpKernel&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0108"target="_blank" rel="noopener"&gt;CVE-2025-0108&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;524&lt;/td&gt;
&lt;td&gt;Palo Alto Networks&lt;/td&gt;
&lt;td&gt;PAN-OS / Cloud NGFW&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-44228"target="_blank" rel="noopener"&gt;CVE-2021-44228&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;493&lt;/td&gt;
&lt;td&gt;Apache Software Foundation&lt;/td&gt;
&lt;td&gt;Apache Log4j2&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-20198"target="_blank" rel="noopener"&gt;CVE-2023-20198&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;472&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;Cisco IOS XE Software&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;462&lt;/td&gt;
&lt;td&gt;Huawei&lt;/td&gt;
&lt;td&gt;HG532&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-9841"target="_blank" rel="noopener"&gt;CVE-2017-9841&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;444&lt;/td&gt;
&lt;td&gt;PHPUnit&lt;/td&gt;
&lt;td&gt;PHPUnit&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-1555"target="_blank" rel="noopener"&gt;CVE-2016-1555&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;437&lt;/td&gt;
&lt;td&gt;Netgear&lt;/td&gt;
&lt;td&gt;WNAP320&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2014-8361"target="_blank" rel="noopener"&gt;CVE-2014-8361&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;435&lt;/td&gt;
&lt;td&gt;Realtek&lt;/td&gt;
&lt;td&gt;Realtek SDK&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-22527"target="_blank" rel="noopener"&gt;CVE-2023-22527&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;434&lt;/td&gt;
&lt;td&gt;Atlassian&lt;/td&gt;
&lt;td&gt;Confluence Data Center&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-12780"target="_blank" rel="noopener"&gt;CVE-2019-12780&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;429&lt;/td&gt;
&lt;td&gt;Belkin&lt;/td&gt;
&lt;td&gt;Wemo Crock-Pot&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29927"target="_blank" rel="noopener"&gt;CVE-2025-29927&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;427&lt;/td&gt;
&lt;td&gt;Vercel&lt;/td&gt;
&lt;td&gt;Next.js&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-3721"target="_blank" rel="noopener"&gt;CVE-2024-3721&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;426&lt;/td&gt;
&lt;td&gt;TBK&lt;/td&gt;
&lt;td&gt;DVR-4104 / DVR-4216&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-6277"target="_blank" rel="noopener"&gt;CVE-2016-6277&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;424&lt;/td&gt;
&lt;td&gt;Netgear&lt;/td&gt;
&lt;td&gt;D6220 / R-series&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;418&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows Server (WSUS)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-10372"target="_blank" rel="noopener"&gt;CVE-2016-10372&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;418&lt;/td&gt;
&lt;td&gt;eir&lt;/td&gt;
&lt;td&gt;D1000 modem&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-1653"target="_blank" rel="noopener"&gt;CVE-2019-1653&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;408&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;Small Business RV320/RV325&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-26855"target="_blank" rel="noopener"&gt;CVE-2021-26855&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;401&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Exchange Server (ProxyLogon)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-42013"target="_blank" rel="noopener"&gt;CVE-2021-42013&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;391&lt;/td&gt;
&lt;td&gt;Apache Software Foundation&lt;/td&gt;
&lt;td&gt;Apache HTTP Server&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-0656"target="_blank" rel="noopener"&gt;CVE-2023-0656&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;380&lt;/td&gt;
&lt;td&gt;SonicWall&lt;/td&gt;
&lt;td&gt;SonicOS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42793"target="_blank" rel="noopener"&gt;CVE-2023-42793&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;377&lt;/td&gt;
&lt;td&gt;JetBrains&lt;/td&gt;
&lt;td&gt;TeamCity&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-13379"target="_blank" rel="noopener"&gt;CVE-2018-13379&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;375&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiOS / FortiProxy&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0282"target="_blank" rel="noopener"&gt;CVE-2025-0282&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;369&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Connect Secure&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-26134"target="_blank" rel="noopener"&gt;CVE-2022-26134&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;366&lt;/td&gt;
&lt;td&gt;Atlassian&lt;/td&gt;
&lt;td&gt;Confluence Data Center&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-38646"target="_blank" rel="noopener"&gt;CVE-2023-38646&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;366&lt;/td&gt;
&lt;td&gt;Metabase&lt;/td&gt;
&lt;td&gt;Metabase&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-25506"target="_blank" rel="noopener"&gt;CVE-2020-25506&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;360&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DNS-320 NAS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-7600"target="_blank" rel="noopener"&gt;CVE-2018-7600&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;355&lt;/td&gt;
&lt;td&gt;Drupal&lt;/td&gt;
&lt;td&gt;Drupal Core (Drupalgeddon 2)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-28995"target="_blank" rel="noopener"&gt;CVE-2024-28995&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;348&lt;/td&gt;
&lt;td&gt;SolarWinds&lt;/td&gt;
&lt;td&gt;Serv-U&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-23752"target="_blank" rel="noopener"&gt;CVE-2023-23752&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;343&lt;/td&gt;
&lt;td&gt;Joomla!&lt;/td&gt;
&lt;td&gt;Joomla! CMS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-36401"target="_blank" rel="noopener"&gt;CVE-2024-36401&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;341&lt;/td&gt;
&lt;td&gt;OSGeo&lt;/td&gt;
&lt;td&gt;GeoServer / GeoTools&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-22274"target="_blank" rel="noopener"&gt;CVE-2022-22274&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;335&lt;/td&gt;
&lt;td&gt;SonicWall&lt;/td&gt;
&lt;td&gt;SonicOS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-4577"target="_blank" rel="noopener"&gt;CVE-2024-4577&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;333&lt;/td&gt;
&lt;td&gt;PHP Group&lt;/td&gt;
&lt;td&gt;PHP&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-8191"target="_blank" rel="noopener"&gt;CVE-2020-8191&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;328&lt;/td&gt;
&lt;td&gt;Citrix&lt;/td&gt;
&lt;td&gt;ADC / Gateway&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61882"target="_blank" rel="noopener"&gt;CVE-2025-61882&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;327&lt;/td&gt;
&lt;td&gt;Oracle Corporation&lt;/td&gt;
&lt;td&gt;Oracle Concurrent Processing (EBS)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2011-3600"target="_blank" rel="noopener"&gt;CVE-2011-3600&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;322&lt;/td&gt;
&lt;td&gt;Apache&lt;/td&gt;
&lt;td&gt;OFBiz&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-32030"target="_blank" rel="noopener"&gt;CVE-2021-32030&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;320&lt;/td&gt;
&lt;td&gt;ASUS&lt;/td&gt;
&lt;td&gt;GT-AC2900 / Lyra Mini Routers&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-26801"target="_blank" rel="noopener"&gt;CVE-2023-26801&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;318&lt;/td&gt;
&lt;td&gt;LB-LINK&lt;/td&gt;
&lt;td&gt;BL-AC1900 / BL-WR9000 routers&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-17506"target="_blank" rel="noopener"&gt;CVE-2019-17506&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;312&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-868L / DIR-817LW&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;307&lt;/td&gt;
&lt;td&gt;Apache Software Foundation&lt;/td&gt;
&lt;td&gt;Apache Tomcat&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8088"target="_blank" rel="noopener"&gt;CVE-2025-8088&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;307&lt;/td&gt;
&lt;td&gt;win.rar GmbH&lt;/td&gt;
&lt;td&gt;WinRAR&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-24919"target="_blank" rel="noopener"&gt;CVE-2024-24919&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;299&lt;/td&gt;
&lt;td&gt;Check Point&lt;/td&gt;
&lt;td&gt;Quantum Security Gateways&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-10108"target="_blank" rel="noopener"&gt;CVE-2016-10108&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;290&lt;/td&gt;
&lt;td&gt;Western Digital&lt;/td&gt;
&lt;td&gt;MyCloud NAS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-3129"target="_blank" rel="noopener"&gt;CVE-2021-3129&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;284&lt;/td&gt;
&lt;td&gt;Laravel&lt;/td&gt;
&lt;td&gt;Ignition&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32433"target="_blank" rel="noopener"&gt;CVE-2025-32433&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;282&lt;/td&gt;
&lt;td&gt;Erlang&lt;/td&gt;
&lt;td&gt;OTP (SSH)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Top 10 Vulnerabilities per Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-per-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-per-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Aggregated from the published monthly reports. The metrics differ slightly
across months (some months use sighting counts, others a curated Top
ranking).&lt;/p&gt;
&lt;h4&gt;January 2025&lt;span class="hx:absolute hx:-mt-20" id="january-2025"&gt;&lt;/span&gt;
&lt;a href="#january-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/02/01/vulnerability-report-january-2025/"&gt;January 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0282"target="_blank" rel="noopener"&gt;CVE-2025-0282&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Connect Secure&lt;/td&gt;
&lt;td&gt;9.0 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-55591"target="_blank" rel="noopener"&gt;CVE-2024-55591&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiOS&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-49113"target="_blank" rel="noopener"&gt;CVE-2024-49113&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows 10 (LDAP)&lt;/td&gt;
&lt;td&gt;7.5 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;8.8 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24085"target="_blank" rel="noopener"&gt;CVE-2025-24085&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apple&lt;/td&gt;
&lt;td&gt;visionOS / iOS&lt;/td&gt;
&lt;td&gt;7.3 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0283"target="_blank" rel="noopener"&gt;CVE-2025-0283&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Connect Secure&lt;/td&gt;
&lt;td&gt;7.0 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;DASAN Networks&lt;/td&gt;
&lt;td&gt;GPON Router&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Huawei&lt;/td&gt;
&lt;td&gt;HG532&lt;/td&gt;
&lt;td&gt;8.8 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-7344"target="_blank" rel="noopener"&gt;CVE-2024-7344&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Radix&lt;/td&gt;
&lt;td&gt;SmartRecovery&lt;/td&gt;
&lt;td&gt;8.2 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-50603"target="_blank" rel="noopener"&gt;CVE-2024-50603&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Aviatrix&lt;/td&gt;
&lt;td&gt;Controller&lt;/td&gt;
&lt;td&gt;10.0 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;February 2025&lt;span class="hx:absolute hx:-mt-20" id="february-2025"&gt;&lt;/span&gt;
&lt;a href="#february-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/03/01/vulnerability-report-february-2025/"&gt;February 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0282"target="_blank" rel="noopener"&gt;CVE-2025-0282&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Connect Secure&lt;/td&gt;
&lt;td&gt;9.0 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-55591"target="_blank" rel="noopener"&gt;CVE-2024-55591&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiOS&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-49113"target="_blank" rel="noopener"&gt;CVE-2024-49113&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows 10 (LDAP)&lt;/td&gt;
&lt;td&gt;7.5 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0283"target="_blank" rel="noopener"&gt;CVE-2025-0283&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Connect Secure&lt;/td&gt;
&lt;td&gt;7.0 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-7344"target="_blank" rel="noopener"&gt;CVE-2024-7344&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Radix&lt;/td&gt;
&lt;td&gt;SmartRecovery&lt;/td&gt;
&lt;td&gt;8.2 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Huawei&lt;/td&gt;
&lt;td&gt;HG532&lt;/td&gt;
&lt;td&gt;8.8 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;DASAN Networks&lt;/td&gt;
&lt;td&gt;GPON Router&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-50603"target="_blank" rel="noopener"&gt;CVE-2024-50603&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Aviatrix&lt;/td&gt;
&lt;td&gt;Controller&lt;/td&gt;
&lt;td&gt;10.0 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;March 2025&lt;span class="hx:absolute hx:-mt-20" id="march-2025"&gt;&lt;/span&gt;
&lt;a href="#march-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/04/01/vulnerability-report-march-2025/"&gt;March 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29927"target="_blank" rel="noopener"&gt;CVE-2025-29927&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Vercel&lt;/td&gt;
&lt;td&gt;Next.js&lt;/td&gt;
&lt;td&gt;167&lt;/td&gt;
&lt;td&gt;9.1 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apache Software Foundation&lt;/td&gt;
&lt;td&gt;Apache Tomcat&lt;/td&gt;
&lt;td&gt;128&lt;/td&gt;
&lt;td&gt;9.2 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1974"target="_blank" rel="noopener"&gt;CVE-2025-1974&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Kubernetes&lt;/td&gt;
&lt;td&gt;ingress-nginx&lt;/td&gt;
&lt;td&gt;86&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-4577"target="_blank" rel="noopener"&gt;CVE-2024-4577&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;PHP Group&lt;/td&gt;
&lt;td&gt;PHP&lt;/td&gt;
&lt;td&gt;83&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22224"target="_blank" rel="noopener"&gt;CVE-2025-22224&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;VMware&lt;/td&gt;
&lt;td&gt;ESXi&lt;/td&gt;
&lt;td&gt;80&lt;/td&gt;
&lt;td&gt;9.3 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24201"target="_blank" rel="noopener"&gt;CVE-2025-24201&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apple&lt;/td&gt;
&lt;td&gt;iOS / iPadOS&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;7.0 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2783"target="_blank" rel="noopener"&gt;CVE-2025-2783&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;72&lt;/td&gt;
&lt;td&gt;8.3 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30066"target="_blank" rel="noopener"&gt;CVE-2025-30066&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;tj-actions&lt;/td&gt;
&lt;td&gt;changed-files&lt;/td&gt;
&lt;td&gt;67&lt;/td&gt;
&lt;td&gt;8.6 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;8.8 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;April 2025&lt;span class="hx:absolute hx:-mt-20" id="april-2025"&gt;&lt;/span&gt;
&lt;a href="#april-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/05/01/vulnerability-report-april-2025/"&gt;April 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22457"target="_blank" rel="noopener"&gt;CVE-2025-22457&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Connect Secure&lt;/td&gt;
&lt;td&gt;188&lt;/td&gt;
&lt;td&gt;9.0 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32433"target="_blank" rel="noopener"&gt;CVE-2025-32433&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Erlang&lt;/td&gt;
&lt;td&gt;OTP (SSH)&lt;/td&gt;
&lt;td&gt;119&lt;/td&gt;
&lt;td&gt;10 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31161"target="_blank" rel="noopener"&gt;CVE-2025-31161&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;CrushFTP&lt;/td&gt;
&lt;td&gt;CrushFTP&lt;/td&gt;
&lt;td&gt;108&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;SAP&lt;/td&gt;
&lt;td&gt;NetWeaver Visual Composer&lt;/td&gt;
&lt;td&gt;101&lt;/td&gt;
&lt;td&gt;10 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29824"target="_blank" rel="noopener"&gt;CVE-2025-29824&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows (CLFS)&lt;/td&gt;
&lt;td&gt;85&lt;/td&gt;
&lt;td&gt;7.8 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24054"target="_blank" rel="noopener"&gt;CVE-2025-24054&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows (NTLM)&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;6.5 (Medium)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30406"target="_blank" rel="noopener"&gt;CVE-2025-30406&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gladinet&lt;/td&gt;
&lt;td&gt;CentreStack&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;9.0 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24200"target="_blank" rel="noopener"&gt;CVE-2025-24200&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apple&lt;/td&gt;
&lt;td&gt;iPadOS&lt;/td&gt;
&lt;td&gt;61&lt;/td&gt;
&lt;td&gt;6.1 (Medium)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;9.8 (Critical)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;8.8 (High)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;May 2025&lt;span class="hx:absolute hx:-mt-20" id="may-2025"&gt;&lt;/span&gt;
&lt;a href="#may-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/06/03/vulnerability-report-may-2025/"&gt;May 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;SAP&lt;/td&gt;
&lt;td&gt;NetWeaver Visual Composer&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4427"target="_blank" rel="noopener"&gt;CVE-2025-4427&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Endpoint Manager Mobile&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-37899"target="_blank" rel="noopener"&gt;CVE-2025-37899&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Linux&lt;/td&gt;
&lt;td&gt;Linux kernel (ksmbd)&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4428"target="_blank" rel="noopener"&gt;CVE-2025-4428&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Ivanti&lt;/td&gt;
&lt;td&gt;Endpoint Manager Mobile&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32756"target="_blank" rel="noopener"&gt;CVE-2025-32756&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiVoice&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4664"target="_blank" rel="noopener"&gt;CVE-2025-4664&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20188"target="_blank" rel="noopener"&gt;CVE-2025-20188&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;IOS XE Software&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-38475"target="_blank" rel="noopener"&gt;CVE-2024-38475&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apache Software Foundation&lt;/td&gt;
&lt;td&gt;HTTP Server&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;June 2025&lt;span class="hx:absolute hx:-mt-20" id="june-2025"&gt;&lt;/span&gt;
&lt;a href="#june-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/07/07/vulnerability-report-june-2025/"&gt;June 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33053"target="_blank" rel="noopener"&gt;CVE-2025-33053&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows (WebDAV)&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49113"target="_blank" rel="noopener"&gt;CVE-2025-49113&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Roundcube&lt;/td&gt;
&lt;td&gt;Webmail&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;NetScaler&lt;/td&gt;
&lt;td&gt;ADC (&amp;ldquo;CitrixBleed 2&amp;rdquo;)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5419"target="_blank" rel="noopener"&gt;CVE-2025-5419&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2783"target="_blank" rel="noopener"&gt;CVE-2025-2783&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6019"target="_blank" rel="noopener"&gt;CVE-2025-6019&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Red Hat&lt;/td&gt;
&lt;td&gt;Red Hat Enterprise Linux&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33073"target="_blank" rel="noopener"&gt;CVE-2025-33073&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows SMB&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6543"target="_blank" rel="noopener"&gt;CVE-2025-6543&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;NetScaler&lt;/td&gt;
&lt;td&gt;ADC&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;July 2025&lt;span class="hx:absolute hx:-mt-20" id="july-2025"&gt;&lt;/span&gt;
&lt;a href="#july-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/08/23/vulnerability-report-july-2025/"&gt;July 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770"target="_blank" rel="noopener"&gt;CVE-2025-53770&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;SharePoint (&amp;ldquo;ToolShell&amp;rdquo;)&lt;/td&gt;
&lt;td&gt;416&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;NetScaler&lt;/td&gt;
&lt;td&gt;ADC&lt;/td&gt;
&lt;td&gt;267&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25257"target="_blank" rel="noopener"&gt;CVE-2025-25257&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiWeb&lt;/td&gt;
&lt;td&gt;145&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6554"target="_blank" rel="noopener"&gt;CVE-2025-6554&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;130&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-47812"target="_blank" rel="noopener"&gt;CVE-2025-47812&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;wftpserver&lt;/td&gt;
&lt;td&gt;Wing FTP Server&lt;/td&gt;
&lt;td&gt;129&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-269G-PWP5-87PP"target="_blank" rel="noopener"&gt;GHSA-269G-PWP5-87PP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;junit-team&lt;/td&gt;
&lt;td&gt;JUnit4&lt;/td&gt;
&lt;td&gt;120&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53771"target="_blank" rel="noopener"&gt;CVE-2025-53771&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;SharePoint&lt;/td&gt;
&lt;td&gt;104&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49706"target="_blank" rel="noopener"&gt;CVE-2025-49706&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;SharePoint&lt;/td&gt;
&lt;td&gt;96&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-78WR-2P64-HPWJ"target="_blank" rel="noopener"&gt;GHSA-78WR-2P64-HPWJ&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apache Software Foundation&lt;/td&gt;
&lt;td&gt;Apache Commons IO&lt;/td&gt;
&lt;td&gt;85&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-5MG8-W23W-74H3"target="_blank" rel="noopener"&gt;GHSA-5MG8-W23W-74H3&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google LLC&lt;/td&gt;
&lt;td&gt;Guava&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;td&gt;Low&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;August 2025&lt;span class="hx:absolute hx:-mt-20" id="august-2025"&gt;&lt;/span&gt;
&lt;a href="#august-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/09/12/vulnerability-report-august-2025/"&gt;August 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8088"target="_blank" rel="noopener"&gt;CVE-2025-8088&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;win.rar GmbH&lt;/td&gt;
&lt;td&gt;WinRAR&lt;/td&gt;
&lt;td&gt;193&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53786"target="_blank" rel="noopener"&gt;CVE-2025-53786&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Exchange Server&lt;/td&gt;
&lt;td&gt;175&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43300"target="_blank" rel="noopener"&gt;CVE-2025-43300&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apple&lt;/td&gt;
&lt;td&gt;macOS / iOS&lt;/td&gt;
&lt;td&gt;128&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6543"target="_blank" rel="noopener"&gt;CVE-2025-6543&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;NetScaler&lt;/td&gt;
&lt;td&gt;ADC&lt;/td&gt;
&lt;td&gt;111&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25256"target="_blank" rel="noopener"&gt;CVE-2025-25256&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiSIEM&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9074"target="_blank" rel="noopener"&gt;CVE-2025-9074&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Docker Desktop&lt;/td&gt;
&lt;td&gt;65&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;61&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;SAP&lt;/td&gt;
&lt;td&gt;NetWeaver Visual Composer&lt;/td&gt;
&lt;td&gt;59&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;NetScaler&lt;/td&gt;
&lt;td&gt;ADC&lt;/td&gt;
&lt;td&gt;52&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;September 2025&lt;span class="hx:absolute hx:-mt-20" id="september-2025"&gt;&lt;/span&gt;
&lt;a href="#september-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/10/03/vulnerability-report-september-2025/"&gt;September 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10585"target="_blank" rel="noopener"&gt;CVE-2025-10585&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;94&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10035"target="_blank" rel="noopener"&gt;CVE-2025-10035&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortra&lt;/td&gt;
&lt;td&gt;GoAnywhere MFT&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-42957"target="_blank" rel="noopener"&gt;CVE-2025-42957&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;SAP&lt;/td&gt;
&lt;td&gt;S/4HANA&lt;/td&gt;
&lt;td&gt;71&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55241"target="_blank" rel="noopener"&gt;CVE-2025-55241&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Entra&lt;/td&gt;
&lt;td&gt;68&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Adobe&lt;/td&gt;
&lt;td&gt;Commerce&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-50264"target="_blank" rel="noopener"&gt;CVE-2024-50264&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Linux&lt;/td&gt;
&lt;td&gt;Linux kernel&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;58&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-51767"target="_blank" rel="noopener"&gt;CVE-2023-51767&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;OpenSSH&lt;/td&gt;
&lt;td&gt;OpenSSH&lt;/td&gt;
&lt;td&gt;57&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;57&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43300"target="_blank" rel="noopener"&gt;CVE-2025-43300&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apple&lt;/td&gt;
&lt;td&gt;iOS / iPadOS&lt;/td&gt;
&lt;td&gt;54&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;October 2025&lt;span class="hx:absolute hx:-mt-20" id="october-2025"&gt;&lt;/span&gt;
&lt;a href="#october-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/11/04/vulnerability-report-october-2025/"&gt;October 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61882"target="_blank" rel="noopener"&gt;CVE-2025-61882&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Oracle Corporation&lt;/td&gt;
&lt;td&gt;Oracle Concurrent Processing (EBS)&lt;/td&gt;
&lt;td&gt;241&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows Server (WSUS)&lt;/td&gt;
&lt;td&gt;235&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49844"target="_blank" rel="noopener"&gt;CVE-2025-49844&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Redis&lt;/td&gt;
&lt;td&gt;Redis&lt;/td&gt;
&lt;td&gt;106&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59489"target="_blank" rel="noopener"&gt;CVE-2025-59489&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Unity3D&lt;/td&gt;
&lt;td&gt;Unity Editor&lt;/td&gt;
&lt;td&gt;98&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61884"target="_blank" rel="noopener"&gt;CVE-2025-61884&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Oracle Corporation&lt;/td&gt;
&lt;td&gt;Oracle Configurator&lt;/td&gt;
&lt;td&gt;95&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Adobe&lt;/td&gt;
&lt;td&gt;Commerce&lt;/td&gt;
&lt;td&gt;94&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55315"target="_blank" rel="noopener"&gt;CVE-2025-55315&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;ASP.NET Core 8.0&lt;/td&gt;
&lt;td&gt;75&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20352"target="_blank" rel="noopener"&gt;CVE-2025-20352&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;IOS&lt;/td&gt;
&lt;td&gt;63&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;63&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;November 2025&lt;span class="hx:absolute hx:-mt-20" id="november-2025"&gt;&lt;/span&gt;
&lt;a href="#november-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2025/12/03/vulnerability-report-november-2025/"&gt;November 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-64446"target="_blank" rel="noopener"&gt;CVE-2025-64446&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiWeb&lt;/td&gt;
&lt;td&gt;105&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows Server (WSUS)&lt;/td&gt;
&lt;td&gt;88&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21042"target="_blank" rel="noopener"&gt;CVE-2025-21042&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Samsung Mobile&lt;/td&gt;
&lt;td&gt;Samsung Mobile Devices&lt;/td&gt;
&lt;td&gt;86&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58034"target="_blank" rel="noopener"&gt;CVE-2025-58034&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiWeb&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13223"target="_blank" rel="noopener"&gt;CVE-2025-13223&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-20198"target="_blank" rel="noopener"&gt;CVE-2023-20198&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;IOS XE Software&lt;/td&gt;
&lt;td&gt;71&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61757"target="_blank" rel="noopener"&gt;CVE-2025-61757&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Oracle Corporation&lt;/td&gt;
&lt;td&gt;Identity Manager&lt;/td&gt;
&lt;td&gt;67&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11001"target="_blank" rel="noopener"&gt;CVE-2025-11001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;7-Zip&lt;/td&gt;
&lt;td&gt;7-Zip&lt;/td&gt;
&lt;td&gt;65&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12480"target="_blank" rel="noopener"&gt;CVE-2025-12480&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;TrioFox&lt;/td&gt;
&lt;td&gt;TrioFox&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;59&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;December 2025&lt;span class="hx:absolute hx:-mt-20" id="december-2025"&gt;&lt;/span&gt;
&lt;a href="#december-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Top vulnerabilities sourced from the
&lt;a href="http://www.vulnerability-lookup.org/2026/01/12/vulnerability-report-december-2025/"&gt;December 2025 report&lt;/a&gt;:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Sightings&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Meta&lt;/td&gt;
&lt;td&gt;react-server-dom-webpack (&amp;ldquo;React2Shell&amp;rdquo;)&lt;/td&gt;
&lt;td&gt;852&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14847"target="_blank" rel="noopener"&gt;CVE-2025-14847&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;MongoDB Inc.&lt;/td&gt;
&lt;td&gt;MongoDB Server&lt;/td&gt;
&lt;td&gt;204&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20393"target="_blank" rel="noopener"&gt;CVE-2025-20393&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;Cisco Secure Email&lt;/td&gt;
&lt;td&gt;89&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;DIR-645&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;ZyXEL&lt;/td&gt;
&lt;td&gt;P660HN-T1A&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14733"target="_blank" rel="noopener"&gt;CVE-2025-14733&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;WatchGuard&lt;/td&gt;
&lt;td&gt;Fireware OS&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66516"target="_blank" rel="noopener"&gt;CVE-2025-66516&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apache Software Foundation&lt;/td&gt;
&lt;td&gt;Apache Tika core&lt;/td&gt;
&lt;td&gt;57&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;DASAN Networks&lt;/td&gt;
&lt;td&gt;GPON Router&lt;/td&gt;
&lt;td&gt;56&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-40602"target="_blank" rel="noopener"&gt;CVE-2025-40602&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;SonicWall&lt;/td&gt;
&lt;td&gt;SMA1000&lt;/td&gt;
&lt;td&gt;53&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59718"target="_blank" rel="noopener"&gt;CVE-2025-59718&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiSwitchManager&lt;/td&gt;
&lt;td&gt;53&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities (CISA, CIRCL, EUVD)&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities-cisa-circl-euvd"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities-cisa-circl-euvd" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;KEV catalogs aggregated by Vulnerability-Lookup. The monthly reports
formally introduced a dedicated &lt;em&gt;Known Exploited Vulnerabilities&lt;/em&gt; section
starting in &lt;strong&gt;September 2025&lt;/strong&gt;. The entries below mirror what was published
in each monthly report between September and December 2025. Earlier 2025
KEV additions (January–August) are tracked in the live
&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"target="_blank" rel="noopener"&gt;CISA&lt;/a&gt; and
&lt;a href="https://euvd.enisa.europa.eu/"target="_blank" rel="noopener"&gt;EUVD&lt;/a&gt; catalogs but were not summarised at
the time. &lt;strong&gt;CIRCL&lt;/strong&gt; is the publisher of Vulnerability-Lookup and curates KEV
data from CISA, EUVD/ENISA, and ad-hoc community sources.&lt;/p&gt;
&lt;h3&gt;CISA KEV&lt;span class="hx:absolute hx:-mt-20" id="cisa-kev"&gt;&lt;/span&gt;
&lt;a href="#cisa-kev" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;September 2025&lt;span class="hx:absolute hx:-mt-20" id="september-2025-1"&gt;&lt;/span&gt;
&lt;a href="#september-2025-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59689"target="_blank" rel="noopener"&gt;CVE-2025-59689&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;IOS&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10035"target="_blank" rel="noopener"&gt;CVE-2025-10035&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;Fortra&lt;/td&gt;
&lt;td&gt;GoAnywhere MFT&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32463"target="_blank" rel="noopener"&gt;CVE-2025-32463&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;Sudo project&lt;/td&gt;
&lt;td&gt;Sudo&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-21311"target="_blank" rel="noopener"&gt;CVE-2021-21311&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;vrana&lt;/td&gt;
&lt;td&gt;adminer&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20352"target="_blank" rel="noopener"&gt;CVE-2025-20352&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;IOS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20333"target="_blank" rel="noopener"&gt;CVE-2025-20333&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;25/09/25&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;ASA Software&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20362"target="_blank" rel="noopener"&gt;CVE-2025-20362&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;25/09/25&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;ASA Software&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10585"target="_blank" rel="noopener"&gt;CVE-2025-10585&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;23/09/25&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5086"target="_blank" rel="noopener"&gt;CVE-2025-5086&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;11/09/25&lt;/td&gt;
&lt;td&gt;Dassault Systèmes&lt;/td&gt;
&lt;td&gt;DELMIA Apriso&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53690"target="_blank" rel="noopener"&gt;CVE-2025-53690&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/09/25&lt;/td&gt;
&lt;td&gt;Sitecore&lt;/td&gt;
&lt;td&gt;Experience Manager (XM)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48543"target="_blank" rel="noopener"&gt;CVE-2025-48543&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/09/25&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Android&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-38352"target="_blank" rel="noopener"&gt;CVE-2025-38352&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/09/25&lt;/td&gt;
&lt;td&gt;Linux&lt;/td&gt;
&lt;td&gt;Linux kernel&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-50224"target="_blank" rel="noopener"&gt;CVE-2023-50224&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;03/09/25&lt;/td&gt;
&lt;td&gt;TP-Link&lt;/td&gt;
&lt;td&gt;TL-WR841N&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9377"target="_blank" rel="noopener"&gt;CVE-2025-9377&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;03/09/25&lt;/td&gt;
&lt;td&gt;TP-Link Systems Inc.&lt;/td&gt;
&lt;td&gt;Archer C7(EU) V2&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-24363"target="_blank" rel="noopener"&gt;CVE-2020-24363&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/09/25&lt;/td&gt;
&lt;td&gt;TP-Link&lt;/td&gt;
&lt;td&gt;TL-WA855RE&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;October 2025&lt;span class="hx:absolute hx:-mt-20" id="october-2025-1"&gt;&lt;/span&gt;
&lt;a href="#october-2025-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-41244"target="_blank" rel="noopener"&gt;CVE-2025-41244&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30/10/25&lt;/td&gt;
&lt;td&gt;VMware&lt;/td&gt;
&lt;td&gt;VCF operations&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24893"target="_blank" rel="noopener"&gt;CVE-2025-24893&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30/10/25&lt;/td&gt;
&lt;td&gt;XWiki&lt;/td&gt;
&lt;td&gt;xwiki-platform&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6205"target="_blank" rel="noopener"&gt;CVE-2025-6205&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28/10/25&lt;/td&gt;
&lt;td&gt;Dassault Systèmes&lt;/td&gt;
&lt;td&gt;DELMIA Apriso&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6204"target="_blank" rel="noopener"&gt;CVE-2025-6204&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28/10/25&lt;/td&gt;
&lt;td&gt;Dassault Systèmes&lt;/td&gt;
&lt;td&gt;DELMIA Apriso&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;24/10/25&lt;/td&gt;
&lt;td&gt;Adobe&lt;/td&gt;
&lt;td&gt;Commerce&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;24/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows Server (WSUS)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61932"target="_blank" rel="noopener"&gt;CVE-2025-61932&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;22/10/25&lt;/td&gt;
&lt;td&gt;MOTEX Inc.&lt;/td&gt;
&lt;td&gt;Lanscope Endpoint Manager&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61884"target="_blank" rel="noopener"&gt;CVE-2025-61884&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;Oracle Corporation&lt;/td&gt;
&lt;td&gt;Oracle Configurator&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-48503"target="_blank" rel="noopener"&gt;CVE-2022-48503&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;Apple&lt;/td&gt;
&lt;td&gt;macOS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2746"target="_blank" rel="noopener"&gt;CVE-2025-2746&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;Kentico&lt;/td&gt;
&lt;td&gt;Xperience&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2747"target="_blank" rel="noopener"&gt;CVE-2025-2747&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;Kentico&lt;/td&gt;
&lt;td&gt;Xperience&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33073"target="_blank" rel="noopener"&gt;CVE-2025-33073&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54253"target="_blank" rel="noopener"&gt;CVE-2025-54253&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15/10/25&lt;/td&gt;
&lt;td&gt;Adobe&lt;/td&gt;
&lt;td&gt;Experience Manager&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-47827"target="_blank" rel="noopener"&gt;CVE-2025-47827&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;IGEL&lt;/td&gt;
&lt;td&gt;IGEL OS&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6264"target="_blank" rel="noopener"&gt;CVE-2025-6264&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;Rapid7&lt;/td&gt;
&lt;td&gt;Velociraptor&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-7836"target="_blank" rel="noopener"&gt;CVE-2016-7836&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;Sky Co., LTD.&lt;/td&gt;
&lt;td&gt;SKYSEA Client View&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59230"target="_blank" rel="noopener"&gt;CVE-2025-59230&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24990"target="_blank" rel="noopener"&gt;CVE-2025-24990&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-43798"target="_blank" rel="noopener"&gt;CVE-2021-43798&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/10/25&lt;/td&gt;
&lt;td&gt;Grafana&lt;/td&gt;
&lt;td&gt;Grafana&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27915"target="_blank" rel="noopener"&gt;CVE-2025-27915&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;07/10/25&lt;/td&gt;
&lt;td&gt;Zimbra&lt;/td&gt;
&lt;td&gt;Collaboration&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-3962"target="_blank" rel="noopener"&gt;CVE-2010-3962&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Internet Explorer&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61882"target="_blank" rel="noopener"&gt;CVE-2025-61882&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;Oracle Corporation&lt;/td&gt;
&lt;td&gt;Oracle Concurrent Processing (EBS)&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-22555"target="_blank" rel="noopener"&gt;CVE-2021-22555&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;Linux / NetApp&lt;/td&gt;
&lt;td&gt;Linux kernel&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-3765"target="_blank" rel="noopener"&gt;CVE-2010-3765&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;Mozilla&lt;/td&gt;
&lt;td&gt;Firefox&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-43226"target="_blank" rel="noopener"&gt;CVE-2021-43226&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2011-3402"target="_blank" rel="noopener"&gt;CVE-2011-3402&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2013-3918"target="_blank" rel="noopener"&gt;CVE-2013-3918&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4008"target="_blank" rel="noopener"&gt;CVE-2025-4008&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;Smartbedded&lt;/td&gt;
&lt;td&gt;MeteoBridge&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-7755"target="_blank" rel="noopener"&gt;CVE-2015-7755&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;Juniper&lt;/td&gt;
&lt;td&gt;ScreenOS&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-1000353"target="_blank" rel="noopener"&gt;CVE-2017-1000353&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;Jenkins&lt;/td&gt;
&lt;td&gt;Jenkins&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2014-6278"target="_blank" rel="noopener"&gt;CVE-2014-6278&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;GNU&lt;/td&gt;
&lt;td&gt;Bash&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21043"target="_blank" rel="noopener"&gt;CVE-2025-21043&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;Samsung Mobile&lt;/td&gt;
&lt;td&gt;Samsung Mobile Devices&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;November 2025&lt;span class="hx:absolute hx:-mt-20" id="november-2025-1"&gt;&lt;/span&gt;
&lt;a href="#november-2025-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48703"target="_blank" rel="noopener"&gt;CVE-2025-48703&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/11/25&lt;/td&gt;
&lt;td&gt;centos-webpanel&lt;/td&gt;
&lt;td&gt;CentOS Web Panel&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11371"target="_blank" rel="noopener"&gt;CVE-2025-11371&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/11/25&lt;/td&gt;
&lt;td&gt;Gladinet&lt;/td&gt;
&lt;td&gt;CentreStack / TrioFox&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21042"target="_blank" rel="noopener"&gt;CVE-2025-21042&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;10/11/25&lt;/td&gt;
&lt;td&gt;Samsung Mobile&lt;/td&gt;
&lt;td&gt;Samsung Mobile Devices&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9242"target="_blank" rel="noopener"&gt;CVE-2025-9242&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/11/25&lt;/td&gt;
&lt;td&gt;WatchGuard&lt;/td&gt;
&lt;td&gt;Fireware OS&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-62215"target="_blank" rel="noopener"&gt;CVE-2025-62215&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/11/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12480"target="_blank" rel="noopener"&gt;CVE-2025-12480&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/11/25&lt;/td&gt;
&lt;td&gt;TrioFox&lt;/td&gt;
&lt;td&gt;TrioFox&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-64446"target="_blank" rel="noopener"&gt;CVE-2025-64446&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/11/25&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiWeb&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58034"target="_blank" rel="noopener"&gt;CVE-2025-58034&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18/11/25&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiWeb&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13223"target="_blank" rel="noopener"&gt;CVE-2025-13223&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19/11/25&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61757"target="_blank" rel="noopener"&gt;CVE-2025-61757&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;21/11/25&lt;/td&gt;
&lt;td&gt;Oracle Corporation&lt;/td&gt;
&lt;td&gt;Identity Manager&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-26829"target="_blank" rel="noopener"&gt;CVE-2021-26829&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28/11/25&lt;/td&gt;
&lt;td&gt;scadabr&lt;/td&gt;
&lt;td&gt;scadabr&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;December 2025&lt;span class="hx:absolute hx:-mt-20" id="december-2025-1"&gt;&lt;/span&gt;
&lt;a href="#december-2025-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14847"target="_blank" rel="noopener"&gt;CVE-2025-14847&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/12/25&lt;/td&gt;
&lt;td&gt;MongoDB Inc.&lt;/td&gt;
&lt;td&gt;MongoDB Server&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-52163"target="_blank" rel="noopener"&gt;CVE-2023-52163&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;22/12/25&lt;/td&gt;
&lt;td&gt;DigiEver&lt;/td&gt;
&lt;td&gt;DS-2105 Pro&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14733"target="_blank" rel="noopener"&gt;CVE-2025-14733&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19/12/25&lt;/td&gt;
&lt;td&gt;WatchGuard&lt;/td&gt;
&lt;td&gt;Fireware OS&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20393"target="_blank" rel="noopener"&gt;CVE-2025-20393&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17/12/25&lt;/td&gt;
&lt;td&gt;Cisco&lt;/td&gt;
&lt;td&gt;Cisco Secure Email&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-40602"target="_blank" rel="noopener"&gt;CVE-2025-40602&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17/12/25&lt;/td&gt;
&lt;td&gt;SonicWall&lt;/td&gt;
&lt;td&gt;SMA1000&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59374"target="_blank" rel="noopener"&gt;CVE-2025-59374&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17/12/25&lt;/td&gt;
&lt;td&gt;ASUS&lt;/td&gt;
&lt;td&gt;Live Update&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59718"target="_blank" rel="noopener"&gt;CVE-2025-59718&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;16/12/25&lt;/td&gt;
&lt;td&gt;Fortinet&lt;/td&gt;
&lt;td&gt;FortiSwitchManager&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43529"target="_blank" rel="noopener"&gt;CVE-2025-43529&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15/12/25&lt;/td&gt;
&lt;td&gt;Apple&lt;/td&gt;
&lt;td&gt;iOS / iPadOS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14611"target="_blank" rel="noopener"&gt;CVE-2025-14611&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15/12/25&lt;/td&gt;
&lt;td&gt;Gladinet&lt;/td&gt;
&lt;td&gt;CentreStack / TrioFox&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14174"target="_blank" rel="noopener"&gt;CVE-2025-14174&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/12/25&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Chrome&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-4063"target="_blank" rel="noopener"&gt;CVE-2018-4063&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/12/25&lt;/td&gt;
&lt;td&gt;Sierra Wireless&lt;/td&gt;
&lt;td&gt;ALEOS&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58360"target="_blank" rel="noopener"&gt;CVE-2025-58360&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;11/12/25&lt;/td&gt;
&lt;td&gt;GeoServer&lt;/td&gt;
&lt;td&gt;GeoServer&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-62221"target="_blank" rel="noopener"&gt;CVE-2025-62221&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/12/25&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Windows&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6218"target="_blank" rel="noopener"&gt;CVE-2025-6218&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/12/25&lt;/td&gt;
&lt;td&gt;RARLAB&lt;/td&gt;
&lt;td&gt;WinRAR&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66644"target="_blank" rel="noopener"&gt;CVE-2025-66644&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;08/12/25&lt;/td&gt;
&lt;td&gt;Array Networks&lt;/td&gt;
&lt;td&gt;ArrayOS AG&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-37055"target="_blank" rel="noopener"&gt;CVE-2022-37055&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;08/12/25&lt;/td&gt;
&lt;td&gt;D-Link&lt;/td&gt;
&lt;td&gt;GO-RT-AC750&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;05/12/25&lt;/td&gt;
&lt;td&gt;Meta&lt;/td&gt;
&lt;td&gt;react-server-dom-webpack&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-26828"target="_blank" rel="noopener"&gt;CVE-2021-26828&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;03/12/25&lt;/td&gt;
&lt;td&gt;scadabr&lt;/td&gt;
&lt;td&gt;scadabr&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48633"target="_blank" rel="noopener"&gt;CVE-2025-48633&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/12/25&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Android&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48572"target="_blank" rel="noopener"&gt;CVE-2025-48572&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/12/25&lt;/td&gt;
&lt;td&gt;Google&lt;/td&gt;
&lt;td&gt;Android&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;EUVD / ENISA KEV&lt;span class="hx:absolute hx:-mt-20" id="euvd--enisa-kev"&gt;&lt;/span&gt;
&lt;a href="#euvd--enisa-kev" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;September 2025&lt;span class="hx:absolute hx:-mt-20" id="september-2025-2"&gt;&lt;/span&gt;
&lt;a href="#september-2025-2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;VLAI Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25231"target="_blank" rel="noopener"&gt;CVE-2025-25231&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/09/25&lt;/td&gt;
&lt;td&gt;Omnissa&lt;/td&gt;
&lt;td&gt;Workspace ONE UEM&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;October, November, December 2025&lt;span class="hx:absolute hx:-mt-20" id="october-november-december-2025"&gt;&lt;/span&gt;
&lt;a href="#october-november-december-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;No new entry was added to the EUVD / ENISA Known Exploited Vulnerabilities
catalog during October, November and December 2025.&lt;/p&gt;
&lt;h3&gt;CIRCL KEV&lt;span class="hx:absolute hx:-mt-20" id="circl-kev"&gt;&lt;/span&gt;
&lt;a href="#circl-kev" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The CIRCL Known Exploited Vulnerabilities catalog
(&lt;code&gt;catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd&lt;/code&gt;) tracks vulnerabilities
that &lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt; has confirmed exploited based on its
own incident-response, honeypot, and sinkhole telemetry. The entries below
correspond to KEV records with confirmed exploitation activity observed
during 2025:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;First seen&lt;/th&gt;
&lt;th&gt;Last seen&lt;/th&gt;
&lt;th&gt;Evidence source&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-28771"target="_blank" rel="noopener"&gt;CVE-2023-28771&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Zyxel&lt;/td&gt;
&lt;td&gt;ZyWALL/USG, USG FLEX, ATP, VPN, ZLD firmware&lt;/td&gt;
&lt;td&gt;2025-01-01&lt;/td&gt;
&lt;td&gt;2026-01-28&lt;/td&gt;
&lt;td&gt;CIRCL sinkhole (&lt;code&gt;cti-feed.circl.lu&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770"target="_blank" rel="noopener"&gt;CVE-2025-53770&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;SharePoint Server (&amp;ldquo;ToolShell&amp;rdquo;)&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;td&gt;2025-09-30&lt;/td&gt;
&lt;td&gt;CIRCL incident response&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The CIRCL KEV catalog remains intentionally small and high-confidence —
every entry is backed by first-hand evidence collected by CIRCL — which is
why its 2025 footprint is much narrower than the CISA KEV catalog.&lt;/p&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The following community comments and bundles were among the most relevant
content shared on Vulnerability-Lookup during 2025.&lt;/p&gt;
&lt;h3&gt;January&lt;span class="hx:absolute hx:-mt-20" id="january"&gt;&lt;/span&gt;
&lt;a href="#january" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/0ff87615-7549-4602-8c19-766d8fd43c8d"target="_blank" rel="noopener"&gt;Unit42 Threat Brief: CVE-2025-0282 and CVE-2025-0283&lt;/a&gt; — Ivanti Connect Secure exploitation analysis.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/bd1f7e06-4107-433a-9fa6-fbf3db5cfa34"target="_blank" rel="noopener"&gt;CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/602ffeaf-2425-48cc-967c-0efad9629dd0"target="_blank" rel="noopener"&gt;Sonicwall vulnerabilities including critical ones&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/1589f952-6079-4a2c-b742-e8d947b50a39"target="_blank" rel="noopener"&gt;Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/d938dc28-6877-40db-ad5f-25f3051288e6"target="_blank" rel="noopener"&gt;6 vulnerabilities in rsync server&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/ef590220-936b-4bad-a04d-fea5234fae47"target="_blank" rel="noopener"&gt;CISA Releases Fact Sheet Detailing Embedded Backdoor Function of Contec CMS8000 Firmware&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;February&lt;span class="hx:absolute hx:-mt-20" id="february"&gt;&lt;/span&gt;
&lt;a href="#february" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/fdda4963-0aa7-4d15-8a8f-969db8f304ca"target="_blank" rel="noopener"&gt;Black Basta&amp;rsquo;s Leaked Chat Logs&lt;/a&gt; — multi-vendor exploitation tracking from leaked Matrix chat logs.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/92582bf5-d92c-47fe-b891-656d271bbfef"target="_blank" rel="noopener"&gt;Update on SVR Cyber Operations and Vulnerability Exploitation&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/b2a6b85e-5b0d-4ac4-b7a4-9227e3ff28e0"target="_blank" rel="noopener"&gt;SonicWall Firewall Vulnerability Exploited After PoC Publication&lt;/a&gt; for CVE-2024-53704.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/b45703d4-11a4-4f18-a2f4-8929ea2f08d2"target="_blank" rel="noopener"&gt;Out-of-Cycle Security Bulletin: Juniper Session Smart Router auth bypass (CVE-2025-21589)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/a4c1e6ab-1786-4631-8cc9-dfa00c7171a6"target="_blank" rel="noopener"&gt;Threat Actors Use CVE-2019-18935 to Deliver Reverse Shells&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;March&lt;span class="hx:absolute hx:-mt-20" id="march"&gt;&lt;/span&gt;
&lt;a href="#march" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/f5e26632-2e27-44d4-8620-cfc829f6488a"target="_blank" rel="noopener"&gt;VMSA-2025-0004: VMware ESXi, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/84edafcd-42a7-4c30-96f8-87de8e73e1ab"target="_blank" rel="noopener"&gt;Ingress NGINX Controller for Kubernetes — Vulnerabilities fixed in controller-v1.12.1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/9a5e050a-4772-4f07-b3cb-81eae488ff62"target="_blank" rel="noopener"&gt;Kaspersky — Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/2002296b-dd57-45e0-b127-feeaa53cc204"target="_blank" rel="noopener"&gt;Pre-authentication SQL injection to RCE in GLPI (CVE-2025-24799/CVE-2025-24801)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/d41ef7ed-39b6-4408-a718-2c3bce5fc99e"target="_blank" rel="noopener"&gt;StopRansomware: Ghost (Cring) Ransomware | CISA&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;April&lt;span class="hx:absolute hx:-mt-20" id="april"&gt;&lt;/span&gt;
&lt;a href="#april" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/1b563420-7047-49bc-8488-2571aa82709c"target="_blank" rel="noopener"&gt;Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/00b15597-d2d6-413f-b3a1-38c62db1e6b0"target="_blank" rel="noopener"&gt;CVE-2025-24054, NTLM Exploit in the Wild — Checkpoint Research&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/9bbd91e2-309f-4b35-9b31-fc613b3101d9"target="_blank" rel="noopener"&gt;PHP Core Security Audit Results&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/avishaifrad/f4e23a97156b1905a7ec8b962a9f2bc8"target="_blank" rel="noopener"&gt;Check if SAP system is vulnerable to CVE-2025-31324&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/a7120db2-1a20-4a03-849d-4688d5ea7992"target="_blank" rel="noopener"&gt;Path Traversal Vulnerability in Surveillance Software — Luxembourg and Belgium notified&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;May&lt;span class="hx:absolute hx:-mt-20" id="may"&gt;&lt;/span&gt;
&lt;a href="#may" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/48d3bc1d-ce6b-4a0d-93f6-aec07945969d"target="_blank" rel="noopener"&gt;CVE-2025-22252: Authentication bypass in FortiOS, FortiProxy, and FortiSwitchManager&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/eff35358-2a58-408d-8c52-0b1143adc25c"target="_blank" rel="noopener"&gt;CVE-2025-30663: Zoom Workplace privilege escalation&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/a79b754d-9252-4580-8912-42f39c854661"target="_blank" rel="noopener"&gt;CVE-2025-27920: Output Messenger exploited since April 2024&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;June&lt;span class="hx:absolute hx:-mt-20" id="june"&gt;&lt;/span&gt;
&lt;a href="#june" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/07234762-c7df-4dde-a778-fbc97a0c452a"target="_blank" rel="noopener"&gt;CitrixBleed 2 (CVE-2025-5777)&lt;/a&gt; — analysis comparing the flaw to CVE-2023-4966.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0002"target="_blank" rel="noopener"&gt;GCVE-1-2025-0002: Cl0p ransomware data exfiltration utility vulnerable to RCE&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/8d7e5f98-25d6-4fe3-87b8-d71838f2dafb"target="_blank" rel="noopener"&gt;Stuxnet-related CVEs&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/aaaf84c7-8007-4de5-b99f-ae9a91d6e26d"target="_blank" rel="noopener"&gt;CVE-2025-31022: PayU WordPress plugin account takeover&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/85c55b2b-8a7a-4d34-89ec-52e38ed8903c"target="_blank" rel="noopener"&gt;CVE-2025-4517: CPython tarfile library RCE&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;July&lt;span class="hx:absolute hx:-mt-20" id="july"&gt;&lt;/span&gt;
&lt;a href="#july" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/94b37950-f479-444b-bff8-5571bd15eac5"target="_blank" rel="noopener"&gt;Pre-Auth SQL Injection to RCE — Fortinet FortiWeb Fabric Connector (CVE-2025-25257)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/e6381844-1d85-477e-83f0-f85545c99c27"target="_blank" rel="noopener"&gt;Ruckus network management solutions riddled with unpatched vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/419fd7d2-3c77-4032-b717-747015a7b289"target="_blank" rel="noopener"&gt;VMSA-2025-0013: VMware ESXi, Workstation, Fusion, and Tools updates&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;August&lt;span class="hx:absolute hx:-mt-20" id="august"&gt;&lt;/span&gt;
&lt;a href="#august" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/6001a8cc-e4a0-48af-9eaf-7967fc09c50e"target="_blank" rel="noopener"&gt;NetScaler ADC and NetScaler Gateway Security Bulletin (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/4a43bf52-0c47-4127-b278-29316a7c4c3d"target="_blank" rel="noopener"&gt;Citrix forgot to tell you CVE-2025-6543 has been used as a zero day since May 2025&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/b0453b3f-aa70-494d-8cbf-b4217e22de4a"target="_blank" rel="noopener"&gt;Cache Me If You Can — Sitecore Experience Platform cache poisoning to RCE&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;September&lt;span class="hx:absolute hx:-mt-20" id="september"&gt;&lt;/span&gt;
&lt;a href="#september" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/43ff9e04-da8f-45fe-a06a-e8f9b84a2d14"target="_blank" rel="noopener"&gt;SAP Security Patch Day — September 2025&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/289697c2-61dc-410f-8343-aba0be87728d"target="_blank" rel="noopener"&gt;npm.js — account &lt;code&gt;qix&lt;/code&gt; and &lt;code&gt;duckdb_admin&lt;/code&gt; compromised and associated CVEs allocated&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/0878ff81-bcad-48b4-b1e5-06b610a5939d"target="_blank" rel="noopener"&gt;Cisco AnyConnect/ASA — vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/b9b7b7f7-7795-4351-bb65-6204702ae05d"target="_blank" rel="noopener"&gt;Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;October&lt;span class="hx:absolute hx:-mt-20" id="october"&gt;&lt;/span&gt;
&lt;a href="#october" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/834a30cc-c06c-49b3-9157-eb77f711c73f"target="_blank" rel="noopener"&gt;F5 — K000156572: Quarterly Security Notification (October 2025)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/acbcdcf4-c6b1-4f9e-a2b8-7053fda7238d"target="_blank" rel="noopener"&gt;OpenSSL Security Advisory&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/19771c30-1865-418d-8329-9b74748acb52"target="_blank" rel="noopener"&gt;Indicators of Compromise (IOCs) for CVE-2025-59287 (WSUS)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/b7668c06-85ed-4e3f-ab33-77c996b4e48b"target="_blank" rel="noopener"&gt;Growing speculation that the Red Hat compromise may be linked to a recently disclosed vulnerability in Red Hat OpenShift AI&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;November&lt;span class="hx:absolute hx:-mt-20" id="november"&gt;&lt;/span&gt;
&lt;a href="#november" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/c4273ed6-7073-4456-bb8f-28d2b213259b"target="_blank" rel="noopener"&gt;RCE in Agent DVR&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/3b6bbd4e-9be5-48b3-8a2d-10b2b5f5da17"target="_blank" rel="noopener"&gt;Amazon discovers APT exploiting Cisco and Citrix zero-days&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/647bd131-5525-47ea-8d98-53d132cabe2e"target="_blank" rel="noopener"&gt;Suricata 8.0.2 and 7.0.13 released — including multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/3d3050ec-b24b-4cf2-b07d-6fa859b0f201"target="_blank" rel="noopener"&gt;UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;December&lt;span class="hx:absolute hx:-mt-20" id="december"&gt;&lt;/span&gt;
&lt;a href="#december" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/6739b288-995a-4f1a-9f03-5d1ced3a8fbd"target="_blank" rel="noopener"&gt;React2Shell (CVE-2025-55182)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/816dcc8e-f25a-4895-9b59-1bbd9caeccb8"target="_blank" rel="noopener"&gt;The LAST Linux 5.4.y release. It is now end-of-life and should not be used by anyone, anymore.&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/63aa0cf1-252d-490e-8492-fbddac588c54"target="_blank" rel="noopener"&gt;Apache Tika (CVE-2025-66516)&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/c5b7cfe4-31dc-48ad-9aad-8e8bd3c6bf83"target="_blank" rel="noopener"&gt;Security content of iOS 26.2 and iPadOS 26.2&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/fa5775cb-515d-41b8-b18e-c17a50ec6630"target="_blank" rel="noopener"&gt;Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A heartfelt thank you to all the contributors, source maintainers, and
users who reported sightings, posted comments, curated bundles, and
provided feedback throughout 2025. Vulnerability-Lookup is a community
effort, and the depth of this year-in-review is a direct reflection of
your engagement. Special thanks to the
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;Shadowserver Foundation&lt;/a&gt;, the
&lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP project&lt;/a&gt;, the
&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"target="_blank" rel="noopener"&gt;CISA KEV&lt;/a&gt;,
the &lt;a href="https://euvd.enisa.europa.eu/"target="_blank" rel="noopener"&gt;EUVD / ENISA&lt;/a&gt; team, and the many
researchers who share information openly with the community.&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can
&lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub
repository. Your feedback is invaluable to us:
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You can also explore and reuse the AI tooling that produced this report:
&lt;strong&gt;VulnMCP&lt;/strong&gt; — &lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/VulnMCP&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of the Federated European Team for Threat Analysis
(&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;)
is the improvement of Cyber Threat Intelligence (CTI) products available
to the public and private sectors in Poland, Luxembourg, and the European
Union as a whole. Developing actionable CTI products (reports, indicators,
etc.) is a complex task and requires an in-depth understanding of the
threat landscape and the ability to analyse and interpret large amounts
of data. Many SOCs and CSIRTs build their capabilities in this area
independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg
(&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative
designed to provide a systematic response facility to computer security
threats and incidents. The organisation brings to the table its
extensive experience in cybersecurity incident management, threat
intelligence, and proactive response strategies. With a strong
background in developing innovative open source cybersecurity tools and
solutions, CIRCL&amp;rsquo;s contribution to the FETTA project is instrumental in
achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - April 2026</title><link>http://www.vulnerability-lookup.org/2026/05/04/vulnerability-report-april-2026/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/05/04/vulnerability-report-april-2026/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated with the help of AI, using the
&lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;VulnMCP&lt;/a&gt; tooling on top of
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform&amp;rsquo;s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerabilities for April 2026, based on data
aggregated from &lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;, the
&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"target="_blank" rel="noopener"&gt;CISA Known Exploited Vulnerabilities&lt;/a&gt;
catalog, the &lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt; KEV catalog, the
&lt;a href="https://euvd.enisa.europa.eu/"target="_blank" rel="noopener"&gt;ENISA EUVD&lt;/a&gt; feed, and contributor comments and bundles.
Sightings come from &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky,
&lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/TeleGramSight"target="_blank" rel="noopener"&gt;Telegram&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;,
&lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, &lt;a href="https://github.com/rapid7/metasploit-framework"target="_blank" rel="noopener"&gt;Metasploit&lt;/a&gt;,
and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;April 2026 was dominated by a Linux kernel crypto subsystem flaw, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-31431"target="_blank" rel="noopener"&gt;CVE-2026-31431&lt;/a&gt; (&amp;ldquo;Copy Fail&amp;rdquo;), an algif_aead in-place operation regression that drew 279 sightings &amp;ndash; by far the highest activity of the month. Local privilege escalation against shared multi-user Linux hosts and container infrastructure (including Microsoft WSL) was confirmed in the wild, and CISA added the entry to its KEV catalog on May 1.&lt;/p&gt;
&lt;p&gt;Edge-security appliances and developer tooling shaped the rest of the top ranking. Fortinet &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-35616"target="_blank" rel="noopener"&gt;FortiClient EMS&lt;/a&gt; (improper access control, CVSS 9.1) was added to both the CISA and CIRCL KEV catalogs on April 6, and a related FortiClient EMS SQLi &amp;ndash; &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21643"target="_blank" rel="noopener"&gt;CVE-2026-21643&lt;/a&gt; &amp;ndash; was KEV-listed on April 13. Adobe Acrobat Reader prototype-pollution &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34621"target="_blank" rel="noopener"&gt;CVE-2026-34621&lt;/a&gt; and GitHub Enterprise Server git-push option injection &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3854"target="_blank" rel="noopener"&gt;CVE-2026-3854&lt;/a&gt; both crossed 140 sightings, while Apache ActiveMQ &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34197"target="_blank" rel="noopener"&gt;CVE-2026-34197&lt;/a&gt; (Jolokia/Spring code injection) followed closely.&lt;/p&gt;
&lt;p&gt;A burst of &amp;ldquo;AI-stack&amp;rdquo; exposure also marked the month: &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-39987"target="_blank" rel="noopener"&gt;marimo&lt;/a&gt; (pre-auth RCE via an unauthenticated terminal WebSocket) was added to KEV on April 23, and Meta React Server Components &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt; (KEV since December 2025, known ransomware use) continued to rack up sightings as scanning persisted.&lt;/p&gt;
&lt;p&gt;The end of the month brought a critical hosting-stack incident: WebPros &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-41940"target="_blank" rel="noopener"&gt;cPanel &amp;amp; WHM CVE-2026-41940&lt;/a&gt;, an authentication bypass in the login flow (CVSS 9.8), was disclosed on April 28-29 and added to CISA KEV on April 30 with a 3-day remediation deadline.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; added 30 entries during April. Highlights:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-41940"target="_blank" rel="noopener"&gt;CVE-2026-41940&lt;/a&gt;: WebPros cPanel &amp;amp; WHM authentication bypass&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-39987"target="_blank" rel="noopener"&gt;CVE-2026-39987&lt;/a&gt;: marimo pre-auth RCE&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34197"target="_blank" rel="noopener"&gt;CVE-2026-34197&lt;/a&gt;: Apache ActiveMQ code injection via Jolokia&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-35616"target="_blank" rel="noopener"&gt;CVE-2026-35616&lt;/a&gt;: Fortinet FortiClient EMS improper access control&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34621"target="_blank" rel="noopener"&gt;CVE-2026-34621&lt;/a&gt;: Adobe Acrobat &amp;amp; Reader prototype pollution&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1340"target="_blank" rel="noopener"&gt;CVE-2026-1340&lt;/a&gt;: Ivanti Endpoint Manager Mobile (EPMM) RCE&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-32201"target="_blank" rel="noopener"&gt;CVE-2026-32201&lt;/a&gt;: Microsoft SharePoint Server spoofing&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3502"target="_blank" rel="noopener"&gt;CVE-2026-3502&lt;/a&gt;: TrueConf Client update integrity bypass&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-5281"target="_blank" rel="noopener"&gt;CVE-2026-5281&lt;/a&gt;: Google Chrome / Dawn use-after-free&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;CISA also re-anchored attention on long-standing exploited issues &amp;ndash; ConnectWise ScreenConnect (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-1708"target="_blank" rel="noopener"&gt;CVE-2024-1708&lt;/a&gt;), SimpleHelp (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-57726"target="_blank" rel="noopener"&gt;CVE-2024-57726&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-57728"target="_blank" rel="noopener"&gt;CVE-2024-57728&lt;/a&gt;), Samsung MagicINFO (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-7399"target="_blank" rel="noopener"&gt;CVE-2024-7399&lt;/a&gt;), JetBrains TeamCity (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-27199"target="_blank" rel="noopener"&gt;CVE-2024-27199&lt;/a&gt;), PaperCut NG (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-27351"target="_blank" rel="noopener"&gt;CVE-2023-27351&lt;/a&gt;), Microsoft Exchange (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-21529"target="_blank" rel="noopener"&gt;CVE-2023-21529&lt;/a&gt;) and even legacy Microsoft Office issues from 2009/2012 (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2009-0238"target="_blank" rel="noopener"&gt;CVE-2009-0238&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2012-1854"target="_blank" rel="noopener"&gt;CVE-2012-1854&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;CIRCL Known Exploited Vulnerabilities catalog&lt;/a&gt; added one entry: &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-35616"target="_blank" rel="noopener"&gt;CVE-2026-35616&lt;/a&gt; (Fortinet FortiClient EMS), confirmed via incident-response evidence. The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;ENISA EUVD KEV catalog&lt;/a&gt; had no new entries in April.&lt;/p&gt;
&lt;p&gt;Contributor activity in April focused on operational mitigations for the Linux kernel &amp;ldquo;Copy Fail&amp;rdquo; issue, with practical SELinux, systemd &lt;code&gt;RestrictAddressFamilies&lt;/code&gt;, and &lt;code&gt;initcall_blacklist&lt;/code&gt; recipes shared by community members.&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-31431"target="_blank" rel="noopener"&gt;CVE-2026-31431&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;279&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Kernel (algif_aead)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9482)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34621"target="_blank" rel="noopener"&gt;CVE-2026-34621&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;147&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Acrobat&amp;#43;Reader"target="_blank" rel="noopener"&gt;Acrobat Reader&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.997)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-35616"target="_blank" rel="noopener"&gt;CVE-2026-35616&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;142&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiClientEMS"target="_blank" rel="noopener"&gt;FortiClient EMS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9572)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3854"target="_blank" rel="noopener"&gt;CVE-2026-3854&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;142&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GitHub"target="_blank" rel="noopener"&gt;GitHub&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GitHub&amp;amp;product=Enterprise&amp;#43;Server"target="_blank" rel="noopener"&gt;Enterprise Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8704)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34197"target="_blank" rel="noopener"&gt;CVE-2026-34197&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;138&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache&amp;#43;Software&amp;#43;Foundation"target="_blank" rel="noopener"&gt;Apache&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache&amp;#43;Software&amp;#43;Foundation&amp;amp;product=Apache&amp;#43;ActiveMQ"target="_blank" rel="noopener"&gt;ActiveMQ&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.6661)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;111&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta"target="_blank" rel="noopener"&gt;Meta&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta&amp;amp;product=react-server-dom-webpack"target="_blank" rel="noopener"&gt;React Server Components&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9934)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-5281"target="_blank" rel="noopener"&gt;CVE-2026-5281&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;104&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome (Dawn)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9874)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-39987"target="_blank" rel="noopener"&gt;CVE-2026-39987&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;96&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=marimo-team"target="_blank" rel="noopener"&gt;marimo-team&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=marimo-team&amp;amp;product=marimo"target="_blank" rel="noopener"&gt;marimo&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9856)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-41940"target="_blank" rel="noopener"&gt;CVE-2026-41940&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;92&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WebPros"target="_blank" rel="noopener"&gt;WebPros&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WebPros&amp;amp;product=cPanel"target="_blank" rel="noopener"&gt;cPanel &amp;amp; WHM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8211)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-32201"target="_blank" rel="noopener"&gt;CVE-2026-32201&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;91&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=SharePoint"target="_blank" rel="noopener"&gt;SharePoint Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5863)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-32202"target="_blank" rel="noopener"&gt;CVE-2026-32202&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-28&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows"target="_blank" rel="noopener"&gt;Windows Shell&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.8578)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-1708"target="_blank" rel="noopener"&gt;CVE-2024-1708&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-28&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ConnectWise"target="_blank" rel="noopener"&gt;ConnectWise&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ConnectWise&amp;amp;product=ScreenConnect"target="_blank" rel="noopener"&gt;ScreenConnect&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.6127)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-57726"target="_blank" rel="noopener"&gt;CVE-2024-57726&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-24&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SimpleHelp"target="_blank" rel="noopener"&gt;SimpleHelp&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SimpleHelp&amp;amp;product=SimpleHelp"target="_blank" rel="noopener"&gt;SimpleHelp&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7288)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-57728"target="_blank" rel="noopener"&gt;CVE-2024-57728&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-24&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SimpleHelp"target="_blank" rel="noopener"&gt;SimpleHelp&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SimpleHelp&amp;amp;product=SimpleHelp"target="_blank" rel="noopener"&gt;SimpleHelp&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8902)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-7399"target="_blank" rel="noopener"&gt;CVE-2024-7399&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-24&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Electronics"target="_blank" rel="noopener"&gt;Samsung&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Electronics&amp;amp;product=MagicINFO&amp;#43;9&amp;#43;Server"target="_blank" rel="noopener"&gt;MagicINFO 9 Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.6987)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29635"target="_blank" rel="noopener"&gt;CVE-2025-29635&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-24&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link"target="_blank" rel="noopener"&gt;D-Link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link&amp;amp;product=DIR-823X"target="_blank" rel="noopener"&gt;DIR-823X&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9867)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-39987"target="_blank" rel="noopener"&gt;CVE-2026-39987&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-23&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=marimo-team"target="_blank" rel="noopener"&gt;marimo-team&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=marimo-team&amp;amp;product=marimo"target="_blank" rel="noopener"&gt;marimo&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9856)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33825"target="_blank" rel="noopener"&gt;CVE-2026-33825&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-22&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Defender&amp;#43;Antimalware&amp;#43;Platform"target="_blank" rel="noopener"&gt;Defender Antimalware Platform&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9396)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-27199"target="_blank" rel="noopener"&gt;CVE-2024-27199&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=JetBrains"target="_blank" rel="noopener"&gt;JetBrains&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=JetBrains&amp;amp;product=TeamCity"target="_blank" rel="noopener"&gt;TeamCity&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.785)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32975"target="_blank" rel="noopener"&gt;CVE-2025-32975&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Quest"target="_blank" rel="noopener"&gt;Quest&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Quest&amp;amp;product=KACE&amp;#43;SMA"target="_blank" rel="noopener"&gt;KACE Systems Management Appliance&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8677)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20128"target="_blank" rel="noopener"&gt;CVE-2026-20128&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN&amp;#43;Manager"target="_blank" rel="noopener"&gt;Catalyst SD-WAN Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5543)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48700"target="_blank" rel="noopener"&gt;CVE-2025-48700&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Synacor"target="_blank" rel="noopener"&gt;Synacor&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Synacor&amp;amp;product=Zimbra&amp;#43;Collaboration&amp;#43;Suite&amp;#43;%28ZCS%29"target="_blank" rel="noopener"&gt;Zimbra Collaboration Suite&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9744)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-27351"target="_blank" rel="noopener"&gt;CVE-2023-27351&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=PaperCut"target="_blank" rel="noopener"&gt;PaperCut&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=PaperCut&amp;amp;product=NG"target="_blank" rel="noopener"&gt;NG&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7781)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2749"target="_blank" rel="noopener"&gt;CVE-2025-2749&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Kentico"target="_blank" rel="noopener"&gt;Kentico&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Kentico&amp;amp;product=Xperience"target="_blank" rel="noopener"&gt;Xperience&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9762)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20133"target="_blank" rel="noopener"&gt;CVE-2026-20133&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN&amp;#43;Manager"target="_blank" rel="noopener"&gt;Catalyst SD-WAN Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7295)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20122"target="_blank" rel="noopener"&gt;CVE-2026-20122&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN&amp;#43;Manager"target="_blank" rel="noopener"&gt;Catalyst SD-WAN Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9478)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34197"target="_blank" rel="noopener"&gt;CVE-2026-34197&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-16&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache&amp;#43;Software&amp;#43;Foundation"target="_blank" rel="noopener"&gt;Apache&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache&amp;#43;Software&amp;#43;Foundation&amp;amp;product=Apache&amp;#43;ActiveMQ"target="_blank" rel="noopener"&gt;ActiveMQ&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.6661)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-32201"target="_blank" rel="noopener"&gt;CVE-2026-32201&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-14&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=SharePoint"target="_blank" rel="noopener"&gt;SharePoint Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5863)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2009-0238"target="_blank" rel="noopener"&gt;CVE-2009-0238&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-14&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Office&amp;#43;Excel"target="_blank" rel="noopener"&gt;Office Excel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5354)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-34621"target="_blank" rel="noopener"&gt;CVE-2026-34621&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Acrobat&amp;#43;Reader"target="_blank" rel="noopener"&gt;Acrobat Reader&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.997)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21643"target="_blank" rel="noopener"&gt;CVE-2026-21643&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiClientEMS"target="_blank" rel="noopener"&gt;FortiClient EMS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9881)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-9715"target="_blank" rel="noopener"&gt;CVE-2020-9715&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Adobe&amp;#43;Acrobat&amp;#43;and&amp;#43;Reader"target="_blank" rel="noopener"&gt;Acrobat &amp;amp; Reader&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8726)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-36424"target="_blank" rel="noopener"&gt;CVE-2023-36424&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows"target="_blank" rel="noopener"&gt;Windows CLFS Driver&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9933)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-21529"target="_blank" rel="noopener"&gt;CVE-2023-21529&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Exchange&amp;#43;Server"target="_blank" rel="noopener"&gt;Exchange Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.6307)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-60710"target="_blank" rel="noopener"&gt;CVE-2025-60710&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows"target="_blank" rel="noopener"&gt;Host Process for Windows Tasks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9957)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2012-1854"target="_blank" rel="noopener"&gt;CVE-2012-1854&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Office"target="_blank" rel="noopener"&gt;Office VBE6 / VBA&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.954)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1340"target="_blank" rel="noopener"&gt;CVE-2026-1340&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-08&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint&amp;#43;Manager&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile (EPMM)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9867)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-35616"target="_blank" rel="noopener"&gt;CVE-2026-35616&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-06&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiClientEMS"target="_blank" rel="noopener"&gt;FortiClient EMS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9572)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3502"target="_blank" rel="noopener"&gt;CVE-2026-3502&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-02&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TrueConf"target="_blank" rel="noopener"&gt;TrueConf&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TrueConf&amp;amp;product=TrueConf&amp;#43;Client"target="_blank" rel="noopener"&gt;TrueConf Client&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9884)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-5281"target="_blank" rel="noopener"&gt;CVE-2026-5281&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-01&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome / Dawn&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9874)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CISA Catalog.&lt;/p&gt;
&lt;h3&gt;CIRCL&lt;span class="hx:absolute hx:-mt-20" id="circl"&gt;&lt;/span&gt;
&lt;a href="#circl" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-35616"target="_blank" rel="noopener"&gt;CVE-2026-35616&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-04-06&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiClientEMS"target="_blank" rel="noopener"&gt;FortiClient EMS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9572)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CIRCL Catalog.&lt;/p&gt;
&lt;h3&gt;ENISA (EUVD)&lt;span class="hx:absolute hx:-mt-20" id="enisa-euvd"&gt;&lt;/span&gt;
&lt;a href="#enisa-euvd" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;No new entry in April.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the ENISA Catalog.&lt;/p&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Community members focused on operational mitigations for the Linux kernel &amp;ldquo;Copy Fail&amp;rdquo; issue, sharing concrete defensive recipes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/015dc7f6-33e1-49b4-af56-d27f0111165a"target="_blank" rel="noopener"&gt;Quick remediation for CVE-2026-31431 (algif_aead &amp;ldquo;Copy Fail&amp;rdquo;)&lt;/a&gt; &amp;ndash; unloading the &lt;code&gt;algif_aead&lt;/code&gt; kernel module, blacklisting via &lt;code&gt;modprobe.d&lt;/code&gt;, and &lt;code&gt;initcall_blacklist=algif_aead_init&lt;/code&gt; for kernels with the module compiled in.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/22701e2f-15d4-44db-9df9-7e7cdb26d102"target="_blank" rel="noopener"&gt;Microsoft WSL is also vulnerable to CVE-2026-31431&lt;/a&gt; &amp;ndash; pointer to the Microsoft WSL issue tracker confirming impact on Windows hosts running WSL.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/5e9c3f17-4570-484f-9113-fab5ca85b815"target="_blank" rel="noopener"&gt;Deny alg_socket to Containers with SELinux to Mitigate CVE-2026-31431&lt;/a&gt; &amp;ndash; end-to-end SELinux deny-rule walk-through plus &lt;code&gt;systemd-run -p RestrictAddressFamilies=~AF_ALG&lt;/code&gt; and &lt;code&gt;SystemCallArchitectures=native&lt;/code&gt; mitigations for non-container services.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The recurring theme across these contributions: AF_ALG / &lt;code&gt;algif_aead&lt;/code&gt; is rarely needed by user workloads, so disabling it at the kernel, container-runtime, or systemd-unit boundary is a pragmatic mitigation while distributions roll out the corrected kernel patches.&lt;/p&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL&amp;rsquo;s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 4.5.0 released</title><link>http://www.vulnerability-lookup.org/2026/04/30/vulnerability-lookup-4-5-0/</link><pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/04/30/vulnerability-lookup-4-5-0/</guid><description>
&lt;p&gt;We are pleased to announce the release of &lt;strong&gt;Vulnerability-Lookup 4.5.0&lt;/strong&gt;!&lt;/p&gt;
&lt;p&gt;This release strengthens Vulnerability-Lookup on both data collection and analysis.&lt;/p&gt;
&lt;p&gt;We now ingest sightings from &lt;a href="https://github.com/vulnerability-lookup/TeleGramSight"target="_blank" rel="noopener"&gt;Telegram channels&lt;/a&gt;, with roughly 200,000 Telegram sigthings collected so far.
Each vulnerability page also gains new interactive visualisations: sighting type repartition, source repartition, and an experimental adaptive forecast based on the &lt;a href="https://github.com/vulnerability-lookup/TARDISSight"target="_blank" rel="noopener"&gt;TARDISSight&lt;/a&gt; prototype.&lt;/p&gt;
&lt;p&gt;TARDISSight was presented last week in Munich during the &lt;a href="https://www.first.org/conference/firstcti26/"target="_blank" rel="noopener"&gt;FIRST CTI Conference&lt;/a&gt;, and the related paper is available on &lt;a href="https://arxiv.org/abs/2604.16038"target="_blank" rel="noopener"&gt;arXiv&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The EPSS feeder has also been substantially reworked for lower memory usage and more reliable ingestion.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Screencast&lt;span class="hx:absolute hx:-mt-20" id="screencast"&gt;&lt;/span&gt;
&lt;a href="#screencast" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The screencast below gives a quick overview of the new charts, filtering interactions, and forecast behavior introduced in 4.5.0.&lt;/p&gt;
&lt;video class="video-shortcode" preload="auto" controls&gt;
&lt;source src="http://www.vulnerability-lookup.org/images/news/2026/04/Vulnerability-Lookup-4.5.0.webm" type="video/webm"&gt;
There should have been a video here but your browser does not seem
to support it.
&lt;/video&gt;
&lt;p&gt;If your browser cannot play WebM inline, you can still download the file directly from &lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/Vulnerability-Lookup-4.5.0.webm"&gt;this link&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Highlights&lt;span class="hx:absolute hx:-mt-20" id="highlights"&gt;&lt;/span&gt;
&lt;a href="#highlights" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;new: [sightings] Sightings can now originate from Telegram channels via the companion Vulnerability-Lookup &lt;a href="https://github.com/vulnerability-lookup/TeleGramSight"target="_blank" rel="noopener"&gt;Telegram sighting tool&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;new: [templates] Three new tabs on every vulnerability page: sighting type repartition (pie chart), source repartition (pie chart grouping URLs by hostname and collapsing Telegram and MISP feeds), and an experimental adaptive forecast (logistic when the trend is rising, exponential decay when falling — a JavaScript port of the TARDISSight prototype). Each chart is interactive and filters the sightings table when clicked.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d8bfc88"target="_blank" rel="noopener"&gt;d8bfc88&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/8e2ed8c"target="_blank" rel="noopener"&gt;8e2ed8c&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0640874"target="_blank" rel="noopener"&gt;0640874&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d573e31"target="_blank" rel="noopener"&gt;d573e31&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: [templates] Display trend slope (linear fit on daily counts) near the sightings chart.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7e22eb0"target="_blank" rel="noopener"&gt;7e22eb0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: [sightings] Optional &lt;code&gt;content&lt;/code&gt; field on the Sighting model and API.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/4923f87"target="_blank" rel="noopener"&gt;4923f87&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: [templates] Add download/correlations icons to the sightings table on the vuln page.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/6de9cf1"target="_blank" rel="noopener"&gt;6de9cf1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Screenshots&lt;span class="hx:absolute hx:-mt-20" id="screenshots"&gt;&lt;/span&gt;
&lt;a href="#screenshots" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/Forecast.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/Forecast.png" alt="Adaptive forecast chart on a vulnerability page" loading="lazy" /&gt;&lt;/a&gt;
&lt;em&gt;Adaptive forecast view based on the observed trend.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/Source_repartition_1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/Source_repartition_1.png" alt="Source repartition chart grouped by source hostnames" loading="lazy" /&gt;&lt;/a&gt;
&lt;em&gt;Source repartition chart, including grouped feed origins.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/Type_repartition_1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/Type_repartition_1.png" alt="Sighting type repartition chart with table filtering" loading="lazy" /&gt;&lt;/a&gt;
&lt;em&gt;Sighting type repartition chart with interactive filtering.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/Type_repartition_2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/Type_repartition_2.png" alt="Alternate view of the sighting type repartition chart" loading="lazy" /&gt;&lt;/a&gt;
&lt;em&gt;Alternative chart state for a different vulnerability timeline.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Click any image to view it in full size.&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;chg: [api] Use case-insensitive substring match for the sighting source filter.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/db8e14f"target="_blank" rel="noopener"&gt;db8e14f&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [schema] Align Sighting JSON schema with the model.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/67cc01f"target="_blank" rel="noopener"&gt;67cc01f&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Index page now displays published proofs of concept instead of confirmed sightings.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/8908ce3"target="_blank" rel="noopener"&gt;8908ce3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [security] Switch markdown URL sanitizer to a scheme allowlist.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/347c9b4"target="_blank" rel="noopener"&gt;347c9b4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [feeders] EPSS feeder improvements: configurable ingestion from Kvrocks with API fallback, Redis pipelining, year-boundary fix, reduced memory usage, error handling for GitHub API calls. EPSS scores are no longer published on the Redis pub/sub channel.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/939d800"target="_blank" rel="noopener"&gt;939d800&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/eabc5ad"target="_blank" rel="noopener"&gt;eabc5ad&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a9be57e"target="_blank" rel="noopener"&gt;a9be57e&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2a1c75d"target="_blank" rel="noopener"&gt;2a1c75d&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7d9867b"target="_blank" rel="noopener"&gt;7d9867b&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/054d4ab"target="_blank" rel="noopener"&gt;054d4ab&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9a0822e"target="_blank" rel="noopener"&gt;9a0822e&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9277d03"target="_blank" rel="noopener"&gt;9277d03&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ac9a9f4"target="_blank" rel="noopener"&gt;ac9a9f4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Improve full-text search UX and clarify exact vs approximate matching.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/05d5ef9"target="_blank" rel="noopener"&gt;05d5ef9&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [dependencies] The project now requires Python &amp;gt;=3.11,&amp;lt;4.0; restrict myst-parser to Python ≥3.11; updated gevent.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/69d36da"target="_blank" rel="noopener"&gt;69d36da&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/27d1300"target="_blank" rel="noopener"&gt;27d1300&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/28bad8c"target="_blank" rel="noopener"&gt;28bad8c&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [dependencies] Updated Python and JavaScript dependencies.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/74902de"target="_blank" rel="noopener"&gt;74902de&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9d5ab76"target="_blank" rel="noopener"&gt;9d5ab76&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/44fe2a2"target="_blank" rel="noopener"&gt;44fe2a2&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ecb766e"target="_blank" rel="noopener"&gt;ecb766e&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [github] Added issue templates and pull request template.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d4a74b8"target="_blank" rel="noopener"&gt;d4a74b8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [documentation] Updated README and contributor notes.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/09aca11"target="_blank" rel="noopener"&gt;09aca11&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/8ed689f"target="_blank" rel="noopener"&gt;8ed689f&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;fix: [security] Hardened several DOM-injection sites against XSS, including escaping vendor/product and vulnerability ID in the sightings correlations tooltip; URLs are now normalized before the scheme check.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/68b96c8"target="_blank" rel="noopener"&gt;68b96c8&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e4f4da0"target="_blank" rel="noopener"&gt;e4f4da0&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/205dad1"target="_blank" rel="noopener"&gt;205dad1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [forecast] Restrict decay fit to post-peak data so the forecast cannot contradict the observed trend.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/acd8425"target="_blank" rel="noopener"&gt;acd8425&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [disclosure] Warn about CSRF expiry on the new disclosure form and extend token lifetime.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/baff893"target="_blank" rel="noopener"&gt;baff893&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [templates] Long credit names no longer break layout.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/cc267fe"target="_blank" rel="noopener"&gt;cc267fe&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.5.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.5.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real-time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>CIRCL AI approach at the International Committee of the Red Cross (ICRC)</title><link>http://www.vulnerability-lookup.org/2026/04/29/icrc-circl-ai-approaches-in-practice/</link><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/04/29/icrc-circl-ai-approaches-in-practice/</guid><description>
&lt;p&gt;On April 28, 2026, we had the opportunity to present the CIRCL AI approach at the International Committee of the Red Cross (ICRC).
The session took place in Luxembourg, with remote participation from the Delegation for Cyberspace at the Global Cyber Hub in Geneva.&lt;/p&gt;
&lt;p&gt;The objective of this event was practical: show how AI can be used as an operational capability in vulnerability intelligence, not just as a research topic.
We focused on production workflows that help analysts deliver faster, more consistent, and more actionable results.&lt;/p&gt;
&lt;h2&gt;What We Covered&lt;span class="hx:absolute hx:-mt-20" id="what-we-covered"&gt;&lt;/span&gt;
&lt;a href="#what-we-covered" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;During the session, we presented concrete AI use cases developed around Vulnerability-Lookup and related CIRCL initiatives, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Classification and enrichment workflows for vulnerability records, including &lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI&lt;/a&gt; and &lt;a href="https://huggingface.co/CIRCL"target="_blank" rel="noopener"&gt;our models&lt;/a&gt; published on Hugging Face.&lt;/li&gt;
&lt;li&gt;Prioritization support when signals are sparse, noisy, or bursty.&lt;/li&gt;
&lt;li&gt;Reproducible pipelines with human review checkpoints, so final decisions remain analyst-driven.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We also presented AI usage in two other operational projects at CIRCL:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AIL Project&lt;/strong&gt;: applying multiple models for inference tasks on the large-scale AIL dataset.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MISP Project&lt;/strong&gt;: integrating AI-assisted workflows to support threat intelligence analysis and data handling.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We also briefly presented &lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;VulnMCP&lt;/a&gt;, our open-source MCP server, and its orchestrated skills.&lt;/p&gt;
&lt;p&gt;Across these projects, we rely on a mix of models, including excellent open-weight Chinese models, selected according to clear criteria: task fit, inference speed, quality on real data, explainability, and operational robustness. CIRCL is convinced of the importance of open-weight models.&lt;/p&gt;
&lt;h2&gt;Why It Matters&lt;span class="hx:absolute hx:-mt-20" id="why-it-matters"&gt;&lt;/span&gt;
&lt;a href="#why-it-matters" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Security teams are often asked to make high-impact decisions under time pressure and with incomplete information.
Our approach is designed for these conditions by combining open vulnerability data, domain knowledge, and machine-learning components that are measurable and testable.&lt;/p&gt;
&lt;p&gt;In short, the goal is to improve triage quality and response speed while preserving traceability, reproducibility, and analyst oversight.&lt;/p&gt;
&lt;h2&gt;Key Takeaways&lt;span class="hx:absolute hx:-mt-20" id="key-takeaways"&gt;&lt;/span&gt;
&lt;a href="#key-takeaways" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;AI is most effective when embedded in existing analyst workflows.&lt;/li&gt;
&lt;li&gt;Data quality and explainability are as important as model performance.&lt;/li&gt;
&lt;li&gt;Practical, incremental deployment delivers more value than one-shot automation.&lt;/li&gt;
&lt;li&gt;A portfolio of models is often more effective than a single-model strategy for production environments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Presentation Material&lt;span class="hx:absolute hx:-mt-20" id="presentation-material"&gt;&lt;/span&gt;
&lt;a href="#presentation-material" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.vulnerability-lookup.org/files/events/2026/ICRC-AI-At-CIRCl.pdf"&gt;Download the slides (PDF)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter issues or have suggestions, please feel free to open a ticket on our GitHub repository.
Your feedback is invaluable to us: &lt;a href="mailto:info@circl.lu"&gt;info@circl.lu&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 4.4.0 released</title><link>http://www.vulnerability-lookup.org/2026/04/09/vulnerability-lookup-4-4-0/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/04/09/vulnerability-lookup-4-4-0/</guid><description>
&lt;p&gt;We are pleased to announce the release of &lt;strong&gt;Vulnerability-Lookup 4.4.0&lt;/strong&gt;!&lt;/p&gt;
&lt;p&gt;This release introduces &lt;a href="https://vulnerability.circl.lu/disclosures/"target="_blank" rel="noopener"&gt;public disclosure list views&lt;/a&gt;,
enhanced sightings with automatic creation and heatmap navigation controls, toggleable chart events, and configurable CVD policy alerts.
It also includes numerous fixes for database stability and performance, notification reliability, and Meilisearch error handling.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://www.vulnerability-lookup.org/documentation/"target="_blank" rel="noopener"&gt;technical documentation&lt;/a&gt; has been revamped for greater clarity and expanded with deployment guidance for high-traffic environments, validated in our production setup handling 15,000–20,000 queries per second (public API + Web pages).&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;new: [views] Add public disclosures list view and improve disclosure detail template.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ac97550"target="_blank" rel="noopener"&gt;ac97550&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: [heatmap] Add navigation and zoom controls to sightings heatmap.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/57c1fb8"target="_blank" rel="noopener"&gt;57c1fb8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: [sightings] Add toggleable extra events (published, reserved, KEV) to sightings charts.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1ae5cdf"target="_blank" rel="noopener"&gt;1ae5cdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: [sightings] Add backfill_sightings script to create sightings from existing data.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3c036b3"target="_blank" rel="noopener"&gt;3c036b3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;new: [sightings] Automatically create sightings when bundles, comments, or KEV entries are created.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5676730"target="_blank" rel="noopener"&gt;5676730&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/eb20f85"target="_blank" rel="noopener"&gt;eb20f85&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/351d538"target="_blank" rel="noopener"&gt;351d538&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Disclosed Vulnerabilities (CVD process)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Disclosures part of the CVD process are now listed on a dedicated page once they are disclosed (the CVD feature can be disabled in Vulnerability-Lookup).
Previously, they were publicly accessible but not listed in a single view.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/disclosed-vulnerabilities.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/disclosed-vulnerabilities.png" alt="List view of publicly disclosed vulnerabilities in the CVD process" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Comments as a sighting&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Creating a comment on a vulnerability now automatically generates a sighting.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/comment-sighting.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/comment-sighting.png" alt="Comment automatically created as a sighting entry" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Displaying reserved and published dates in the sightings visualisations&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/display-reserved-published-with-sightings.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/display-reserved-published-with-sightings.png" alt="Sightings chart showing reserved and published date markers" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23456#sightings"target="_blank" rel="noopener"&gt;CVE-2026-23456&lt;/a&gt; was mentioned in the list of Ghost CVEs in our &lt;a href="https://www.vulnerability-lookup.org/2026/03/02/vulnerability-report-february-2026/#ghost-cve-report"target="_blank" rel="noopener"&gt;February Vulnerability Report&lt;/a&gt;. The CVE record is now available, and the visualisations show our sightings predating the publication date.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;KEV entry as exploited sightings&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Creating a KEV entry — whether directly, via synchronisation from another Vulnerability-Lookup instance, or by pulling from the CISA or ENISA catalogs — now automatically generates a sighting.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/kev-exploited-sighting.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/kev-exploited-sighting.png" alt="KEV entry displayed as an exploited sighting in the chart" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/kev-sighting.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/kev-sighting.png" alt="KEV sighting details view" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Zoom feature for the sightings visualisations&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/04/sightings-zoom.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/04/sightings-zoom.png" alt="Zoom and navigation controls on the sightings heatmap" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;chg: [config] Make CVD policy alert messages configurable (CVD_POLICY_TITLE, CVD_POLICY_URL, CVD_POLICY_LOGIN_MESSAGE).
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/38a9fc8"target="_blank" rel="noopener"&gt;38a9fc8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [views] Set disclosed_timestamp when admin transitions disclosure state to disclosed.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/b1265ca"target="_blank" rel="noopener"&gt;b1265ca&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Link vulnerability ID, affected products, and CWEs in disclosure detail page.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0b57f62"target="_blank" rel="noopener"&gt;0b57f62&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/c7f750e"target="_blank" rel="noopener"&gt;c7f750e&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/24512cf"target="_blank" rel="noopener"&gt;24512cf&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7dde7dc"target="_blank" rel="noopener"&gt;7dde7dc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] GCVE vulnerabilities show a parenthesized link to the associated CVE ID.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2944a32"target="_blank" rel="noopener"&gt;2944a32&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Vulnerabilities from FSTEC use the severity classification model.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9896c18"target="_blank" rel="noopener"&gt;9896c18&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [documentation] Convert documentation to Markdown and improvements.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/af2de56"target="_blank" rel="noopener"&gt;af2de56&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ba70b69"target="_blank" rel="noopener"&gt;ba70b69&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/54d004b"target="_blank" rel="noopener"&gt;54d004b&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/497c45a"target="_blank" rel="noopener"&gt;497c45a&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [dependencies] Updated Python and JavaScript dependencies.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/81ea0d7"target="_blank" rel="noopener"&gt;81ea0d7&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/af81a41"target="_blank" rel="noopener"&gt;af81a41&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ab94807"target="_blank" rel="noopener"&gt;ab94807&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7706a5c"target="_blank" rel="noopener"&gt;7706a5c&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/b7cfab2"target="_blank" rel="noopener"&gt;b7cfab2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;fix: [views] Skip timestamp check for disclosed state in disclosures query.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/88f8fe9"target="_blank" rel="noopener"&gt;88f8fe9&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [models] Handle None values in Product and Organization field validators.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3f56d34"target="_blank" rel="noopener"&gt;3f56d34&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/078eb1d"target="_blank" rel="noopener"&gt;078eb1d&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [fulltext] Auto-purge Meilisearch tasks on no_space_left_on_device error.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e7ffbfa"target="_blank" rel="noopener"&gt;e7ffbfa&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [database] Fix DetachedInstanceError and idle-in-transaction timeouts.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/801eefd"target="_blank" rel="noopener"&gt;801eefd&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9b89ce3"target="_blank" rel="noopener"&gt;9b89ce3&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/028da84"target="_blank" rel="noopener"&gt;028da84&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [notifications] Release DB transaction before slow email rendering/sending.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1c1a552"target="_blank" rel="noopener"&gt;1c1a552&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/913ecc1"target="_blank" rel="noopener"&gt;913ecc1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [tags] Sync comment tags with upstream MISP vulnerability taxonomy.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5b3d08f"target="_blank" rel="noopener"&gt;5b3d08f&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [forms] Align SignupForm login max length with database constraint.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/210594a"target="_blank" rel="noopener"&gt;210594a&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [bundle] Use JSONB contains operator for bundle vuln_id filter.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/80c7295"target="_blank" rel="noopener"&gt;80c7295&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [sightings] Use KEV asserted_at date for backfilled sighting timestamp.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/8c7d455"target="_blank" rel="noopener"&gt;8c7d455&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.4.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.4.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real-time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>New Russian Severity Classifier and Improved Multilingual Models</title><link>http://www.vulnerability-lookup.org/2026/04/06/russian-severity-classifier/</link><pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/04/06/russian-severity-classifier/</guid><description>
&lt;p&gt;We are pleased to announce a new Russian-language severity classifier for vulnerability descriptions,
alongside improved English and Chinese models. These models are trained with
&lt;a href="https://github.com/vulnerability-lookup/VulnTrain"target="_blank" rel="noopener"&gt;VulnTrain&lt;/a&gt; and served through
&lt;a href="https://github.com/vulnerability-lookup/ML-Gateway"target="_blank" rel="noopener"&gt;ML-Gateway&lt;/a&gt; for integration into
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;All datasets and models are openly available on &lt;a href="https://huggingface.co/CIRCL"target="_blank" rel="noopener"&gt;Hugging Face&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;VulnTrain 3.1.0&lt;span class="hx:absolute hx:-mt-20" id="vulntrain-310"&gt;&lt;/span&gt;
&lt;a href="#vulntrain-310" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This release is powered by &lt;a href="https://github.com/vulnerability-lookup/VulnTrain/releases/tag/v3.1.0"target="_blank" rel="noopener"&gt;VulnTrain v3.1.0&lt;/a&gt;, which introduces:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;FSTEC source support&lt;/strong&gt;: vulnerability entries from the Russian Federal Service for Technical and Export Control (BDU) can now be used for dataset generation and model training.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Source field in datasets&lt;/strong&gt;: each vulnerability entry now includes a &lt;code&gt;source&lt;/code&gt; field identifying its origin (cvelistv5, github, pysec, cnvd, csaf_*, fstec), making it easier to trace and filter data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dynamic dataset cards&lt;/strong&gt;: when generating a dataset from multiple sources, a dataset card is automatically created with a per-source breakdown table showing entry counts and percentages.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Per-class metrics&lt;/strong&gt;: the severity trainer now reports precision, recall, and F1 per class (Low / Medium / High / Critical) alongside overall accuracy and macro F1.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Best model checkpoint selection&lt;/strong&gt;: models are now selected by accuracy instead of eval_loss, with &lt;code&gt;save_total_limit&lt;/code&gt; increased from 2 to 3.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Russian Severity Classifier 🇷🇺&lt;span class="hx:absolute hx:-mt-20" id="russian-severity-classifier-"&gt;&lt;/span&gt;
&lt;a href="#russian-severity-classifier-" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This is our new model for classifying vulnerability severity in Russian, trained on data from the
&lt;a href="https://vulnerability.circl.lu/recent#fstec"target="_blank" rel="noopener"&gt;Russian Federal Service for Technical and Export Control (BDU)&lt;/a&gt;.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Dataset&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/datasets/CIRCL/Vulnerability-FSTEC"target="_blank" rel="noopener"&gt;CIRCL/Vulnerability-FSTEC&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Model&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-russian-ruRoberta-large"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-severity-classification-russian-ruRoberta-large&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Base model&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/ai-forever/ruRoberta-large"target="_blank" rel="noopener"&gt;ai-forever/ruRoberta-large&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Improved English Severity Classifier 🇬🇧&lt;span class="hx:absolute hx:-mt-20" id="improved-english-severity-classifier-"&gt;&lt;/span&gt;
&lt;a href="#improved-english-severity-classifier-" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The English model is trained on a broad set of sources for better coverage and accuracy.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/recent#cvelistv5"target="_blank" rel="noopener"&gt;CVE Program&lt;/a&gt; (enriched with vulnrichment and Fraunhofer FKIE)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/recent#github"target="_blank" rel="noopener"&gt;GitHub Security Advisories&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/recent#pysec"target="_blank" rel="noopener"&gt;PySec advisories&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/recent#csaf_cisco"target="_blank" rel="noopener"&gt;CSAF Cisco&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/recent#csaf_cisa"target="_blank" rel="noopener"&gt;CSAF CISA&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Dataset&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/datasets/CIRCL/vulnerability-scores"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-scores&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Model&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-severity-classification-roberta-base&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Base model&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/FacebookAI/roberta-base"target="_blank" rel="noopener"&gt;FacebookAI/roberta-base&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Improved Chinese Severity Classifier 🇨🇳&lt;span class="hx:absolute hx:-mt-20" id="improved-chinese-severity-classifier-"&gt;&lt;/span&gt;
&lt;a href="#improved-chinese-severity-classifier-" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The Chinese model is trained on data from the &lt;a href="https://vulnerability.circl.lu/recent#cnvd"target="_blank" rel="noopener"&gt;China National Vulnerability Database (CNVD)&lt;/a&gt;.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Dataset&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/datasets/CIRCL/Vulnerability-CNVD"target="_blank" rel="noopener"&gt;CIRCL/Vulnerability-CNVD&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Model&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-chinese-macbert-base"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-severity-classification-chinese-macbert-base&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Base model&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://huggingface.co/hfl/chinese-macbert-base"target="_blank" rel="noopener"&gt;hfl/chinese-macbert-base&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;ML-Gateway 0.5.0&lt;span class="hx:absolute hx:-mt-20" id="ml-gateway-050"&gt;&lt;/span&gt;
&lt;a href="#ml-gateway-050" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://github.com/vulnerability-lookup/ML-Gateway"target="_blank" rel="noopener"&gt;ML-Gateway&lt;/a&gt; is the FastAPI-based inference server that loads pre-trained models at startup
and exposes them through a RESTful API. It supports multilingual severity classification out of the box:
clients simply specify the desired model in their request.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/vulnerability-lookup/ML-Gateway/releases/tag/v0.5.0"target="_blank" rel="noopener"&gt;ML-Gateway v0.5.0&lt;/a&gt; adds support for the new Russian severity classification model
(&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-russian-ruRoberta-large"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-severity-classification-russian-ruRoberta-large&lt;/a&gt;):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registered the Russian ruRoBERTa-large model in the model registry with standard CVSS severity labels (Low, Medium, High, Critical).&lt;/li&gt;
&lt;li&gt;Added the model to the CLI &lt;code&gt;refresh-all&lt;/code&gt; command for pre-downloading.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Vulnerability-Lookup uses ML-Gateway to provide AI-powered severity predictions directly in its web interface.&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://www.linkedin.com/company/aipitch"target="_blank" rel="noopener"&gt;AIPITCH&lt;/a&gt; (AI-Powered Innovative Toolkit for Cybersecurity Hubs) is a co-funded EU
project supported by the European Cybersecurity Competence Centre (ECCC) under the
DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH program and &lt;a href="https://www.circl.lu/"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Improving the CNVD Severity Classifier: Honest Metrics and Data Leakage Fixes</title><link>http://www.vulnerability-lookup.org/2026/04/03/cnvd-severity-classifier-improvements/</link><pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/04/03/cnvd-severity-classifier-improvements/</guid><description>
&lt;p&gt;We recently made significant improvements to our &lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-chinese-macbert-base"target="_blank" rel="noopener"&gt;CNVD severity classifier&lt;/a&gt; and the underlying &lt;a href="https://huggingface.co/datasets/CIRCL/Vulnerability-CNVD"target="_blank" rel="noopener"&gt;Vulnerability-CNVD dataset&lt;/a&gt;, prompted by a thorough independent review from &lt;a href="https://github.com/eromang"target="_blank" rel="noopener"&gt;Eric Romang&lt;/a&gt;. These changes ship in &lt;a href="https://github.com/vulnerability-lookup/VulnTrain/releases/tag/v3.0.0"target="_blank" rel="noopener"&gt;VulnTrain v3.0.0&lt;/a&gt;, released today.&lt;/p&gt;
&lt;h2&gt;What happened&lt;span class="hx:absolute hx:-mt-20" id="what-happened"&gt;&lt;/span&gt;
&lt;a href="#what-happened" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Eric opened &lt;a href="https://github.com/vulnerability-lookup/VulnTrain/issues/19"target="_blank" rel="noopener"&gt;VulnTrain#19&lt;/a&gt; with a detailed technical analysis of the dataset and model. His key findings:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Data leakage&lt;/strong&gt;: CNVD reuses boilerplate descriptions across different vulnerability IDs. Our train/test split was done on IDs, not on description text, so 15.6% of the test set contained descriptions identical to training data. This inflated the reported accuracy by ~1.7pp.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Low-class recall at 38.4%&lt;/strong&gt;: 60% of Low-severity entries were misclassified as Medium. The dataset is heavily imbalanced (Low ~9%, Medium ~55%, High ~36%).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Keyword dependency&lt;/strong&gt;: the model predicts severity based on vulnerability-type keywords rather than actual impact. Accuracy drops from ~89% to ~55% on entries whose severity deviates from the type&amp;rsquo;s typical level.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;His full analysis, code, and data are available at &lt;a href="https://github.com/eromang/researches/tree/main/CNVD-Dataset-Validation"target="_blank" rel="noopener"&gt;eromang/researches/CNVD-Dataset-Validation&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;What we fixed&lt;span class="hx:absolute hx:-mt-20" id="what-we-fixed"&gt;&lt;/span&gt;
&lt;a href="#what-we-fixed" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Data leakage&lt;span class="hx:absolute hx:-mt-20" id="data-leakage"&gt;&lt;/span&gt;
&lt;a href="#data-leakage" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;We implemented a &lt;code&gt;deduplicate_split&lt;/code&gt; function that groups entries by description text before splitting. All entries sharing a description land in the same split. The result: our retrained model scores &lt;strong&gt;76.8% accuracy&lt;/strong&gt; on the deduplicated test set, matching Eric&amp;rsquo;s independently measured unleaked accuracy of &lt;strong&gt;76.6%&lt;/strong&gt;. The model quality was always ~77% — we just have honest metrics now.&lt;/p&gt;
&lt;h3&gt;Class imbalance experiments&lt;span class="hx:absolute hx:-mt-20" id="class-imbalance-experiments"&gt;&lt;/span&gt;
&lt;a href="#class-imbalance-experiments" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;We tested four loss strategies to improve Low-class recall:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Strategy&lt;/th&gt;
&lt;th&gt;Low recall&lt;/th&gt;
&lt;th&gt;Medium recall&lt;/th&gt;
&lt;th&gt;Overall acc&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Uniform (baseline)&lt;/td&gt;
&lt;td&gt;41.0%&lt;/td&gt;
&lt;td&gt;81.7%&lt;/td&gt;
&lt;td&gt;76.8%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sqrt-dampened weights&lt;/td&gt;
&lt;td&gt;49.0%&lt;/td&gt;
&lt;td&gt;74.8%&lt;/td&gt;
&lt;td&gt;74.6%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Balanced weights&lt;/td&gt;
&lt;td&gt;60.8%&lt;/td&gt;
&lt;td&gt;70.2%&lt;/td&gt;
&lt;td&gt;73.2%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Focal loss (gamma=2)&lt;/td&gt;
&lt;td&gt;63.3%&lt;/td&gt;
&lt;td&gt;64.4%&lt;/td&gt;
&lt;td&gt;71.1%&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Every strategy that improved Low recall caused disproportionate Medium recall loss. The Low/Medium vocabulary overlap in CNVD descriptions makes this a data-level ceiling, not a loss-function problem. Eric&amp;rsquo;s own experience with the &lt;a href="https://github.com/eromang/researches/blob/main/CyberScale/docs/lessons-learned.md"target="_blank" rel="noopener"&gt;CyberScale Phase 1&lt;/a&gt; project — predicting 4-class CVSS bands from CVE descriptions using ModernBERT-base — reached the same conclusion: nothing moved the needle beyond ~2pp. Adjacent severity classes share vocabulary because vulnerability descriptions are formulaic.&lt;/p&gt;
&lt;p&gt;We defaulted to &lt;strong&gt;uniform loss&lt;/strong&gt; and documented the Low class limitation.&lt;/p&gt;
&lt;h2&gt;Dataset improvements&lt;span class="hx:absolute hx:-mt-20" id="dataset-improvements"&gt;&lt;/span&gt;
&lt;a href="#dataset-improvements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The &lt;a href="https://huggingface.co/datasets/CIRCL/Vulnerability-CNVD"target="_blank" rel="noopener"&gt;Vulnerability-CNVD&lt;/a&gt; dataset now includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;&lt;code&gt;cve_id&lt;/code&gt; field&lt;/strong&gt; cross-referencing CVE equivalents. Approximately 81% of CNVD entries have a corresponding CVE (68-69% in 2020-2021, rising to 91-97% after 2022). The ~19% CNVD-only entries are concentrated in &lt;strong&gt;Chinese domestic software&lt;/strong&gt; (PHP CMS, ERP systems). Western vendors (Adobe, Microsoft, IBM, Cisco) are &lt;strong&gt;largely absent&lt;/strong&gt; from the CNVD-only subset.&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;dataset card&lt;/strong&gt; documenting severity distribution, CVE overlap rates, and the coverage decline: CNVD published details for 94% of reserved IDs in 2015 but only 4% in 2023. This drop coincides with China&amp;rsquo;s &lt;a href="https://www.chinalawtranslate.com/en/product-security-vulnerabilites/"target="_blank" rel="noopener"&gt;Regulations on the Management of Security Vulnerabilities (RMSV)&lt;/a&gt;, effective September 2021.&lt;/li&gt;
&lt;li&gt;A warning about &lt;strong&gt;duplicate descriptions&lt;/strong&gt; and the need to split on description text rather than IDs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;The RMSV effect&lt;span class="hx:absolute hx:-mt-20" id="the-rmsv-effect"&gt;&lt;/span&gt;
&lt;a href="#the-rmsv-effect" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The RMSV regulations deserve attention. Before September 2021, CNVD published vulnerability details for most of the IDs it reserved. After the regulations took effect, publication rates dropped sharply. As a result, the CNVD dataset is increasingly sparse for recent years and the model&amp;rsquo;s training data is concentrated in pre-2022 entries. Users should be aware of this temporal bias.&lt;/p&gt;
&lt;p&gt;CNVD reserves 50,000–100,000 vulnerability IDs per year but publishes full details for only a fraction. As noted above, the publication rate has declined significantly:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;2015&lt;/strong&gt;: ~94% of reserved IDs have published details&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2023&lt;/strong&gt;: ~4% of reserved IDs have published details&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Model card&lt;span class="hx:absolute hx:-mt-20" id="model-card"&gt;&lt;/span&gt;
&lt;a href="#model-card" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The &lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-chinese-macbert-base"target="_blank" rel="noopener"&gt;model card&lt;/a&gt; is now dynamically generated from actual training metrics and documents the known limitations: Low-class recall, keyword dependency, negation blindness, and CVE overlap.&lt;/p&gt;
&lt;h2&gt;Links&lt;span class="hx:absolute hx:-mt-20" id="links"&gt;&lt;/span&gt;
&lt;a href="#links" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Model: &lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-chinese-macbert-base"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-severity-classification-chinese-macbert-base&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dataset: &lt;a href="https://huggingface.co/datasets/CIRCL/Vulnerability-CNVD"target="_blank" rel="noopener"&gt;CIRCL/Vulnerability-CNVD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Training pipeline: &lt;a href="https://github.com/vulnerability-lookup/VulnTrain"target="_blank" rel="noopener"&gt;VulnTrain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Release: &lt;a href="https://github.com/vulnerability-lookup/VulnTrain/releases/tag/v3.0.0"target="_blank" rel="noopener"&gt;VulnTrain v3.0.0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Issue: &lt;a href="https://github.com/vulnerability-lookup/VulnTrain/issues/19"target="_blank" rel="noopener"&gt;VulnTrain#19&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Eric&amp;rsquo;s analysis: &lt;a href="https://github.com/eromang/researches/tree/main/CNVD-Dataset-Validation"target="_blank" rel="noopener"&gt;CNVD-Dataset-Validation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Technical report: &lt;a href="https://github.com/vulnerability-lookup/VulnTrain/blob/main/docs/cnvd-severity-improvements.md"target="_blank" rel="noopener"&gt;CNVD severity improvements&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Acknowledgments&lt;span class="hx:absolute hx:-mt-20" id="acknowledgments"&gt;&lt;/span&gt;
&lt;a href="#acknowledgments" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thanks to &lt;a href="https://github.com/eromang"target="_blank" rel="noopener"&gt;Eric Romang&lt;/a&gt; for his detailed and constructive analysis. His work directly led to these improvements and confirmed that the model adds real value (+12pp over a keyword heuristic baseline) despite its limitations.&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/europe.png" alt="EU Funding" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.science.nask.pl/en/research-areas/projects/12456"target="_blank" rel="noopener"&gt;AIPITCH&lt;/a&gt; aims to create advanced artificial intelligence-based tools supporting key operational services in cyber defense.
These include technologies for early threat detection, automatic malware classification, and improvement of analytical processes through the integration of Large Language Models (LLM).
The project has the potential to set new standards in the cybersecurity industry.&lt;/p&gt;
&lt;p&gt;The project leader is &lt;a href="https://www.nask.pl/en/institute"target="_blank" rel="noopener"&gt;NASK National Research Institute&lt;/a&gt;. The international consortium includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.circl.lu/"target="_blank" rel="noopener"&gt;CIRCL (Computer Incident Response Center Luxembourg&lt;/a&gt;), Luxembourg&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation, Netherlands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ncbj.gov.pl"target="_blank" rel="noopener"&gt;NCBJ&lt;/a&gt; (National Centre for Nuclear Research), Poland&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.abilab.it"target="_blank" rel="noopener"&gt;ABI LAB&lt;/a&gt; (Centre of Research and Innovation for Banks), Italy&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Cybersecurity Competence Centre.
Neither the European Union nor the European Cybersecurity Competence Centre can be held responsible for them.&lt;/p&gt;</description></item><item><title>Vulnerability Report - March 2026</title><link>http://www.vulnerability-lookup.org/2026/04/02/vulnerability-report-march-2026/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/04/02/vulnerability-report-march-2026/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform&amp;rsquo;s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for March 2026, based on sightings collected from various sources,
including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, &lt;a href="https://github.com/rapid7/metasploit-framework"target="_blank" rel="noopener"&gt;Metasploit&lt;/a&gt;, and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;March 2026 was led by &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3055"target="_blank" rel="noopener"&gt;CVE-2026-3055&lt;/a&gt;, a Critical-severity memory overread in Citrix NetScaler ADC and Gateway when configured as a SAML IDP, with 154 sightings. Active exploitation was confirmed in the wild by multiple sources including honeypot operators, and a proof-of-concept was publicly released by watchTowr. It was followed by &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20131"target="_blank" rel="noopener"&gt;CVE-2026-20131&lt;/a&gt; in Cisco Secure Firewall Management Center (FMC) with 121 sightings &amp;ndash; notably flagged by CISA as having known ransomware campaign use.&lt;/p&gt;
&lt;p&gt;Network appliances and edge devices dominated the threat landscape in March, with Citrix NetScaler, Cisco FMC, and F5 BIG-IP (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53521"target="_blank" rel="noopener"&gt;CVE-2025-53521&lt;/a&gt;) all appearing in both the top sightings and the CISA KEV catalog. AI and workflow automation tools also drew significant attention, with Langflow (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33017"target="_blank" rel="noopener"&gt;CVE-2026-33017&lt;/a&gt;) suffering an unauthenticated RCE via code injection and n8n (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-68613"target="_blank" rel="noopener"&gt;CVE-2025-68613&lt;/a&gt;) being added to CISA KEV. A notable supply-chain entry was the Aquasecurity Trivy embedded malicious code vulnerability (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33634"target="_blank" rel="noopener"&gt;CVE-2026-33634&lt;/a&gt;), which could expose CI/CD credentials.&lt;/p&gt;
&lt;p&gt;On the Linux side, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3888"target="_blank" rel="noopener"&gt;CVE-2026-3888&lt;/a&gt;, a local privilege escalation in snapd affecting multiple Ubuntu LTS versions, attracted 96 sightings. Qualcomm chipset memory corruption (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21385"target="_blank" rel="noopener"&gt;CVE-2026-21385&lt;/a&gt;) was added to CISA KEV early in the month via the Android Security Bulletin. Legacy IoT devices continued to be targeted by botnets such as Mozi, with Zyxel (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;) and D-Link (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;) routers still appearing in the top 10 sightings despite being years old.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; added 26 new entries during the month. Notable additions include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3055"target="_blank" rel="noopener"&gt;CVE-2026-3055&lt;/a&gt;: Citrix NetScaler ADC &amp;amp; Gateway&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20131"target="_blank" rel="noopener"&gt;CVE-2026-20131&lt;/a&gt;: Cisco Secure Firewall Management Center (FMC) &amp;ndash; known ransomware use&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33634"target="_blank" rel="noopener"&gt;CVE-2026-33634&lt;/a&gt;: Aquasecurity Trivy (supply-chain compromise)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33017"target="_blank" rel="noopener"&gt;CVE-2026-33017&lt;/a&gt;: Langflow (unauthenticated RCE)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53521"target="_blank" rel="noopener"&gt;CVE-2025-53521&lt;/a&gt;: F5 BIG-IP (RCE)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54068"target="_blank" rel="noopener"&gt;CVE-2025-54068&lt;/a&gt;: Laravel Livewire (code injection)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;CIRCL Known Exploited Vulnerabilities catalog&lt;/a&gt; added five entries, all confirmed via sinkhole and CTI feed evidence: &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-13030"target="_blank" rel="noopener"&gt;CVE-2024-13030&lt;/a&gt; (D-Link DIR-823G), &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-35394"target="_blank" rel="noopener"&gt;CVE-2021-35394&lt;/a&gt; (Realtek Jungle SDK), &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt; (Huawei HG532), &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2014-8361"target="_blank" rel="noopener"&gt;CVE-2014-8361&lt;/a&gt; (Realtek SDK), and &lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2026-0020"target="_blank" rel="noopener"&gt;GCVE-1-2026-0020&lt;/a&gt; (Eir D1000 router). The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;ENISA KEV catalog&lt;/a&gt; had no new entries in March.&lt;/p&gt;
&lt;p&gt;Contributor insights this month covered Citrix NetScaler CVE-2026-3055 exploitation analysis and PoC details, F5 BIG-IP indicators of compromise, Oracle Identity Manager critical vulnerabilities, BMC FootPrints pre-auth RCE chains, Veeam Backup &amp;amp; Replication security updates, and Lantronix industrial device vulnerabilities.&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3055"target="_blank" rel="noopener"&gt;CVE-2026-3055&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;154&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Citrix"target="_blank" rel="noopener"&gt;Citrix&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Citrix&amp;amp;product=NetScaler"target="_blank" rel="noopener"&gt;NetScaler ADC &amp;amp; Gateway&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9651)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20131"target="_blank" rel="noopener"&gt;CVE-2026-20131&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;121&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Secure&amp;#43;Firewall&amp;#43;Management&amp;#43;Center&amp;#43;%28FMC%29"target="_blank" rel="noopener"&gt;Secure Firewall Management Center (FMC)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.978)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33017"target="_blank" rel="noopener"&gt;CVE-2026-33017&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;101&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Langflow"target="_blank" rel="noopener"&gt;Langflow&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Langflow&amp;amp;product=Langflow"target="_blank" rel="noopener"&gt;Langflow&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9904)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3888"target="_blank" rel="noopener"&gt;CVE-2026-3888&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;96&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Canonical"target="_blank" rel="noopener"&gt;Canonical&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Canonical&amp;amp;product=Ubuntu"target="_blank" rel="noopener"&gt;snapd (Ubuntu)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9876)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21385"target="_blank" rel="noopener"&gt;CVE-2026-21385&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;93&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Qualcomm"target="_blank" rel="noopener"&gt;Qualcomm&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Qualcomm&amp;amp;product=Snapdragon"target="_blank" rel="noopener"&gt;Snapdragon&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9871)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53521"target="_blank" rel="noopener"&gt;CVE-2025-53521&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;87&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=F5"target="_blank" rel="noopener"&gt;F5&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=F5&amp;amp;product=BIG-IP"target="_blank" rel="noopener"&gt;BIG-IP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9364)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21992"target="_blank" rel="noopener"&gt;CVE-2026-21992&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;81&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle"target="_blank" rel="noopener"&gt;Oracle&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;amp;product=Oracle&amp;#43;Identity&amp;#43;Manager"target="_blank" rel="noopener"&gt;Identity Manager &amp;amp; Web Services Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9929)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-32746"target="_blank" rel="noopener"&gt;CVE-2026-32746&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;72&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GNU"target="_blank" rel="noopener"&gt;GNU&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GNU&amp;amp;product=inetutils"target="_blank" rel="noopener"&gt;inetutils (telnetd)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8862)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Zyxel"target="_blank" rel="noopener"&gt;Zyxel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Zyxel&amp;amp;product=P660HN-T1A&amp;#43;Routers"target="_blank" rel="noopener"&gt;P660HN-T1A Router&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.5886)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link"target="_blank" rel="noopener"&gt;D-Link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link&amp;amp;product=DIR-645&amp;#43;Router"target="_blank" rel="noopener"&gt;DIR-645 Router&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.7862)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3055"target="_blank" rel="noopener"&gt;CVE-2026-3055&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-30&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Citrix"target="_blank" rel="noopener"&gt;Citrix&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Citrix&amp;amp;product=NetScaler"target="_blank" rel="noopener"&gt;NetScaler&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9651)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53521"target="_blank" rel="noopener"&gt;CVE-2025-53521&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-27&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=F5"target="_blank" rel="noopener"&gt;F5&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=F5&amp;amp;product=BIG-IP"target="_blank" rel="noopener"&gt;BIG-IP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9364)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33634"target="_blank" rel="noopener"&gt;CVE-2026-33634&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Aquasecurity"target="_blank" rel="noopener"&gt;Aquasecurity&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Aquasecurity&amp;amp;product=Trivy"target="_blank" rel="noopener"&gt;Trivy&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9963)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-33017"target="_blank" rel="noopener"&gt;CVE-2026-33017&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Langflow"target="_blank" rel="noopener"&gt;Langflow&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Langflow&amp;amp;product=Langflow"target="_blank" rel="noopener"&gt;Langflow&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9904)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31277"target="_blank" rel="noopener"&gt;CVE-2025-31277&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Multiple Products&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9935)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43520"target="_blank" rel="noopener"&gt;CVE-2025-43520&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Multiple Products&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.891)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43510"target="_blank" rel="noopener"&gt;CVE-2025-43510&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Multiple Products&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.7061)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54068"target="_blank" rel="noopener"&gt;CVE-2025-54068&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Laravel"target="_blank" rel="noopener"&gt;Laravel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Laravel&amp;amp;product=Livewire"target="_blank" rel="noopener"&gt;Livewire&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9685)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32432"target="_blank" rel="noopener"&gt;CVE-2025-32432&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Craft&amp;#43;CMS"target="_blank" rel="noopener"&gt;Craft CMS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Craft&amp;#43;CMS&amp;amp;product=Craft&amp;#43;CMS"target="_blank" rel="noopener"&gt;Craft CMS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8744)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20131"target="_blank" rel="noopener"&gt;CVE-2026-20131&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-19&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Secure&amp;#43;Firewall&amp;#43;Management&amp;#43;Center&amp;#43;%28FMC%29"target="_blank" rel="noopener"&gt;Secure Firewall Management Center (FMC)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.978)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20963"target="_blank" rel="noopener"&gt;CVE-2026-20963&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-18&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=SharePoint"target="_blank" rel="noopener"&gt;SharePoint&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.6657)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66376"target="_blank" rel="noopener"&gt;CVE-2025-66376&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-18&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Synacor"target="_blank" rel="noopener"&gt;Synacor&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Synacor&amp;amp;product=Zimbra&amp;#43;Collaboration&amp;#43;Suite&amp;#43;%28ZCS%29"target="_blank" rel="noopener"&gt;Zimbra Collaboration Suite (ZCS)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9952)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-47813"target="_blank" rel="noopener"&gt;CVE-2025-47813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-16&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Wing&amp;#43;FTP&amp;#43;Server"target="_blank" rel="noopener"&gt;Wing FTP Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Wing&amp;#43;FTP&amp;#43;Server&amp;amp;product=Wing&amp;#43;FTP&amp;#43;Server"target="_blank" rel="noopener"&gt;Wing FTP Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.8028)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3909"target="_blank" rel="noopener"&gt;CVE-2026-3909&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Skia"target="_blank" rel="noopener"&gt;Skia&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9471)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3910"target="_blank" rel="noopener"&gt;CVE-2026-3910&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chromium&amp;#43;V8"target="_blank" rel="noopener"&gt;Chromium V8&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.98)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-68613"target="_blank" rel="noopener"&gt;CVE-2025-68613&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-11&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=n8n"target="_blank" rel="noopener"&gt;n8n&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=n8n&amp;amp;product=n8n"target="_blank" rel="noopener"&gt;n8n&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8146)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1603"target="_blank" rel="noopener"&gt;CVE-2026-1603&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-09&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint&amp;#43;Manager&amp;#43;%28EPM%29"target="_blank" rel="noopener"&gt;Endpoint Manager (EPM)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9622)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-26399"target="_blank" rel="noopener"&gt;CVE-2025-26399&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-09&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SolarWinds"target="_blank" rel="noopener"&gt;SolarWinds&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SolarWinds&amp;amp;product=Web&amp;#43;Help&amp;#43;Desk"target="_blank" rel="noopener"&gt;Web Help Desk&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9655)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-22054"target="_blank" rel="noopener"&gt;CVE-2021-22054&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-09&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Omnissa"target="_blank" rel="noopener"&gt;Omnissa&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Omnissa&amp;amp;product=Workspace&amp;#43;One&amp;#43;UEM"target="_blank" rel="noopener"&gt;Workspace One UEM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9505)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-41974"target="_blank" rel="noopener"&gt;CVE-2023-41974&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-05&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=iOS&amp;#43;and&amp;#43;iPadOS"target="_blank" rel="noopener"&gt;iOS and iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.997)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-30952"target="_blank" rel="noopener"&gt;CVE-2021-30952&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-05&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Multiple Products&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9971)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-43000"target="_blank" rel="noopener"&gt;CVE-2023-43000&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-05&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Multiple Products&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9948)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-22681"target="_blank" rel="noopener"&gt;CVE-2021-22681&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-05&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Rockwell"target="_blank" rel="noopener"&gt;Rockwell&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Rockwell"target="_blank" rel="noopener"&gt;Multiple Products&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5079)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-7921"target="_blank" rel="noopener"&gt;CVE-2017-7921&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-05&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Hikvision"target="_blank" rel="noopener"&gt;Hikvision&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Hikvision"target="_blank" rel="noopener"&gt;Multiple Products&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9056)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21385"target="_blank" rel="noopener"&gt;CVE-2026-21385&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Qualcomm"target="_blank" rel="noopener"&gt;Qualcomm&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Qualcomm"target="_blank" rel="noopener"&gt;Multiple Chipsets&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9871)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-22719"target="_blank" rel="noopener"&gt;CVE-2026-22719&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Broadcom"target="_blank" rel="noopener"&gt;Broadcom&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Broadcom&amp;amp;product=VMware&amp;#43;Aria&amp;#43;Operations"target="_blank" rel="noopener"&gt;VMware Aria Operations&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.5026)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CISA Catalog.&lt;/p&gt;
&lt;h3&gt;CIRCL&lt;span class="hx:absolute hx:-mt-20" id="circl"&gt;&lt;/span&gt;
&lt;a href="#circl" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-13030"target="_blank" rel="noopener"&gt;CVE-2024-13030&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link"target="_blank" rel="noopener"&gt;D-Link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link&amp;amp;product=DIR-823G"target="_blank" rel="noopener"&gt;DIR-823G&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.5827)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-35394"target="_blank" rel="noopener"&gt;CVE-2021-35394&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Realtek"target="_blank" rel="noopener"&gt;Realtek&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Realtek&amp;amp;product=Jungle&amp;#43;Software&amp;#43;Development&amp;#43;Kit&amp;#43;%28SDK%29"target="_blank" rel="noopener"&gt;Jungle SDK&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9847)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Huawei"target="_blank" rel="noopener"&gt;Huawei&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Huawei&amp;amp;product=HG532"target="_blank" rel="noopener"&gt;HG532&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.4429)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2014-8361"target="_blank" rel="noopener"&gt;CVE-2014-8361&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Realtek"target="_blank" rel="noopener"&gt;Realtek&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Realtek&amp;amp;product=SDK"target="_blank" rel="noopener"&gt;SDK&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9846)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2026-0020"target="_blank" rel="noopener"&gt;GCVE-1-2026-0020&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-03-23&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Eir"target="_blank" rel="noopener"&gt;Eir&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Eir&amp;amp;product=D1000"target="_blank" rel="noopener"&gt;D1000&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.944)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CIRCL Catalog.&lt;/p&gt;
&lt;h3&gt;ENISA&lt;span class="hx:absolute hx:-mt-20" id="enisa"&gt;&lt;/span&gt;
&lt;a href="#enisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;No new entry in March.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the ENISA Catalog.&lt;/p&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/1ae9c3df-c65f-4755-b3a9-4d76f8c0e772"target="_blank" rel="noopener"&gt;NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/a718c241-f3e8-4cc6-b3dc-f71d5790b014"target="_blank" rel="noopener"&gt;Vulnerability CVE-2026-21992 in Oracle Identity Manager and Oracle Web Services Manager&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/47124bb2-b34f-47c1-b0a3-1073423a56ef"target="_blank" rel="noopener"&gt;Critical RCE Vulnerability reported in Windchill&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/8b291831-2785-48c5-bce6-8e1ad5925260"target="_blank" rel="noopener"&gt;The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/08c1bcc5-abc2-4fd7-8a14-32dffe5c9afc"target="_blank" rel="noopener"&gt;Vulnerabilities Resolved in Veeam Backup &amp;amp; Replication 12.3.2.4465&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/49b900ec-633f-4111-a614-2dc8b0b77752"target="_blank" rel="noopener"&gt;Lantronix EDS3000PS and EDS5000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/596d1296-f91f-4f84-a3e6-03aa10878635"target="_blank" rel="noopener"&gt;Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)&lt;/a&gt; &amp;ndash; watchTowr PoC and analysis&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/fdd15828-339e-4711-a71a-6b92792a4aaf"target="_blank" rel="noopener"&gt;CVE-2026-3055 actively exploited in the wild, confirmed by Defused honeypot data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/ccbb9ed0-997c-47b7-b3c1-0758ceb74102"target="_blank" rel="noopener"&gt;K000160486: Indicators of Compromise for F5 BIG-IP CVE-2025-53521&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL&amp;rsquo;s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 4.3.0 released</title><link>http://www.vulnerability-lookup.org/2026/03/27/vulnerability-lookup-4-3-0/</link><pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/03/27/vulnerability-lookup-4-3-0/</guid><description>
&lt;p&gt;We are pleased to announce the release of &lt;strong&gt;Vulnerability-Lookup 4.3.0&lt;/strong&gt;!&lt;/p&gt;
&lt;p&gt;This release brings compliance with the updated &lt;a href="https://gcve.eu/bcp/gcve-bcp-03/"target="_blank" rel="noopener"&gt;GCVE BCP-03&lt;/a&gt; specification (&lt;a href="https://discourse.ossbase.org/t/gcve-bcp-03-review-and-update-required/1033/2"target="_blank" rel="noopener"&gt;discussion&lt;/a&gt;), introducing a dedicated API endpoint for exposing GCVEs published by a local Vulnerability-Lookup instance.
It also includes improvements to the GCVE feeder, email notification reliability fixes, and updated dependencies.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;GCVE Publication Endpoint&lt;span class="hx:absolute hx:-mt-20" id="gcve-publication-endpoint"&gt;&lt;/span&gt;
&lt;a href="#gcve-publication-endpoint" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;A new &lt;code&gt;/api/gcve/publication&lt;/code&gt; endpoint lets external consumers discover all GCVEs published by the local instance.
This is the standard mechanism defined in the updated GCVE BCP-03 for federated vulnerability sharing between Vulnerability-Lookup deployments and GCVE-compatible tools.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/c931b95"target="_blank" rel="noopener"&gt;c931b95&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;GCVE new endpoint&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/gcve-new-endpoint.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/gcve-new-endpoint.png" alt="GCVE new endpoint" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;GCVE publications on db.gcve.eu&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/db-gcve-eu-publications.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/db-gcve-eu-publications.png" alt="GCVE publications on db.gcve.eu" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;GNA-1 publications&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/gna-1-publications.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/gna-1-publications.png" alt="GNA-1 publications" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;chg: [feeder] GCVE feeder now uses /api/gcve/publication with two fallbacks for retro-compatibility.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/96aaed6"target="_blank" rel="noopener"&gt;96aaed6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [bin] Also dump KEV entries.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5523cb7"target="_blank" rel="noopener"&gt;5523cb7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [bin] Updated footer of the dump page.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3260682"target="_blank" rel="noopener"&gt;3260682&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Added a link to the list of sources from the /recent page.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/89723f2"target="_blank" rel="noopener"&gt;89723f2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [dependencies] Updated Python and JavaScript dependencies.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a135d86"target="_blank" rel="noopener"&gt;a135d86&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1fcc515"target="_blank" rel="noopener"&gt;1fcc515&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d163c5f"target="_blank" rel="noopener"&gt;d163c5f&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;fix: [notifications] Remove jitter from last_execution_time to prevent missed notifications. When multiple users subscribed to the same product, the random jitter on last_execution_time created different blind windows, causing some users to miss vulnerability notifications.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a02a9fe"target="_blank" rel="noopener"&gt;a02a9fe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [typing] Fixed a typing issue in the aggregator parameter of the CSAFAggregatorHelper class.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/860ead7"target="_blank" rel="noopener"&gt;860ead7&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.3.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.3.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real-time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>VulnMCP 1.0.0 released</title><link>http://www.vulnerability-lookup.org/2026/03/25/vulnmcp-1-0-0/</link><pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/03/25/vulnmcp-1-0-0/</guid><description>
&lt;p&gt;We are excited to share a new project we have been working on: &lt;strong&gt;VulnMCP&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;VulnMCP&lt;/a&gt; is an MCP server that brings vulnerability intelligence directly into AI clients, chat agents, and automated workflows.
The idea is simple: make vulnerability analysis programmable, modular, and easily consumable by modern AI systems.&lt;/p&gt;
&lt;p&gt;With VulnMCP, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Query and explore vulnerabilities (via Vulnerability-Lookup) directly from your chat agent or editor.&lt;/li&gt;
&lt;li&gt;Classify vulnerability severity (in English and Chinese) using &lt;a href="https://huggingface.co/CIRCL"target="_blank" rel="noopener"&gt;our fine-tuned NLP models&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Predict CWE categories from descriptions.&lt;/li&gt;
&lt;li&gt;Guess the CPE based on one or more keywords from a vulnerability description.&lt;/li&gt;
&lt;li&gt;Explore &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/"target="_blank" rel="noopener"&gt;KEV catalogs&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Retrieve &lt;a href="https://vulnerability.circl.lu/sightings/"target="_blank" rel="noopener"&gt;real-world sightings&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Build and extend your own &amp;ldquo;skills&amp;rdquo; for automated security analysis.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Have a look at the screencast below (with sound on!) featuring Claude Code.
You will see how to retrieve information about a vulnerability using its CVE ID and classify its severity — all from your favorite AI chat agent.&lt;/p&gt;
&lt;video class="video-shortcode" preload="auto" controls&gt;
&lt;source src="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP.webm" type="video/webm"&gt;
There should have been a video here but your browser does not seem
to support it.
&lt;/video&gt;
&lt;p&gt;&lt;strong&gt;Example of CPE Guessing&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/cpe-guessing.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/cpe-guessing.png" alt="CPE guessing" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This AI agent tool uses &lt;a href="https://github.com/vulnerability-lookup/cpe-guesser"target="_blank" rel="noopener"&gt;CPE Guesser&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;VulnMCP is built with a modular architecture, so adding new capabilities is straightforward — whether you want to integrate additional models, data sources, or custom logic.&lt;/p&gt;
&lt;p&gt;This is part of a broader effort to make vulnerability intelligence more accessible, interoperable, and ready for AI-native environments.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Looking into KEV catalogs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-KEV-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-KEV-1.png" alt="Looking into KEV catalogs" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Looking into KEV catalogs and retrieving real-world observations (sightings)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-KEV.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-KEV.png" alt="Looking into KEV catalogs and retrieving sightings" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Finding a GNA and its published vulnerabilities&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-GNA-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-GNA-1.png" alt="VulnMCP GNA - Example 1" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-GNA-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/VulnMCP-GNA-2.png" alt="VulnMCP GNA - Example 2" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Feedback&lt;span class="hx:absolute hx:-mt-20" id="feedback"&gt;&lt;/span&gt;
&lt;a href="#feedback" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you work with MCP clients, LLM agents, or are simply interested in automating vulnerability workflows, give it a try:&lt;/p&gt;
&lt;p&gt;🔗 &lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/VulnMCP&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Feedback, ideas, and contributions are very welcome!&lt;/p&gt;
&lt;h2&gt;References&lt;span class="hx:absolute hx:-mt-20" id="references"&gt;&lt;/span&gt;
&lt;a href="#references" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;The MCP server: &lt;a href="https://github.com/vulnerability-lookup/VulnMCP"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/VulnMCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Training pipelines: &lt;a href="https://github.com/vulnerability-lookup/VulnTrain"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/VulnTrain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Orchestration framework based on XMPP: &lt;a href="https://github.com/vulnerability-lookup/VulnAgent"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/VulnAgent&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Vulnerability-Lookup source code: &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Vulnerability-Lookup instance operated by CIRCL: &lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/europe.png" alt="EU Funding" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.science.nask.pl/en/research-areas/projects/12456"target="_blank" rel="noopener"&gt;AIPITCH&lt;/a&gt; aims to create advanced artificial intelligence-based tools supporting key operational services in cyber defense.
These include technologies for early threat detection, automatic malware classification, and improvement of analytical processes through the integration of Large Language Models (LLM).
The project has the potential to set new standards in the cybersecurity industry.&lt;/p&gt;
&lt;p&gt;The project leader is NASK National Research Institute. The international consortium includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CIRCL (Computer Incident Response Center Luxembourg), Luxembourg&lt;/li&gt;
&lt;li&gt;The Shadowserver Foundation, Netherlands&lt;/li&gt;
&lt;li&gt;NCBJ (National Centre for Nuclear Research), Poland&lt;/li&gt;
&lt;li&gt;ABI LAB (Centre of Research and Innovation for Banks), Italy&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Cybersecurity Competence Centre.
Neither the European Union nor the European Cybersecurity Competence Centre can be held responsible for them.&lt;/p&gt;</description></item><item><title>cpe-guesser 2.0 released - Multi-Source CPE Imports, Better Ranking, and Greater Autonomy Beyond NVD</title><link>http://www.vulnerability-lookup.org/2026/03/22/cpe-guesser-2.0-released/</link><pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/03/22/cpe-guesser-2.0-released/</guid><description>
&lt;h1&gt;cpe-guesser 2.0 released&lt;/h1&gt;&lt;h2&gt;Overview&lt;span class="hx:absolute hx:-mt-20" id="overview"&gt;&lt;/span&gt;
&lt;a href="#overview" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Version 2.0 brings major improvements to CPE import, ranking, and CVE v5 data handling. This release focuses on better import performance, broader format support, improved search relevance, and more robust indexing for vendor and product matching.&lt;/p&gt;
&lt;p&gt;A notable change in this release is that &lt;strong&gt;&lt;a href="https://github.com/vulnerability-lookup/cpe-guesser"target="_blank" rel="noopener"&gt;cpe-guesser&lt;/a&gt; is no longer limited to NVD as its only practical CPE source&lt;/strong&gt;. In addition to the NVD feeds, it can also leverage the &lt;strong&gt;Vulnerability-Lookup dump available at &lt;a href="https://vulnerability.circl.lu/dumps/"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/dumps/&lt;/a&gt;&lt;/strong&gt;, providing &lt;strong&gt;additional CPE sources&lt;/strong&gt; and more &lt;strong&gt;autonomy from the previously NVD-only source model&lt;/strong&gt;.&lt;/p&gt;
&lt;h2&gt;Highlights&lt;span class="hx:absolute hx:-mt-20" id="highlights"&gt;&lt;/span&gt;
&lt;a href="#highlights" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Improved search and ranking&lt;span class="hx:absolute hx:-mt-20" id="improved-search-and-ranking"&gt;&lt;/span&gt;
&lt;a href="#improved-search-and-ranking" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Improved search ranking using CPE rank scores.&lt;/li&gt;
&lt;li&gt;Enhanced server-side lookup ranking with &lt;code&gt;rank:cpe&lt;/code&gt; scoring.&lt;/li&gt;
&lt;li&gt;Reset of CVE v5 rank state before each import to ensure consistent ranking behavior.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;CVE v5 import and indexing enhancements&lt;span class="hx:absolute hx:-mt-20" id="cve-v5-import-and-indexing-enhancements"&gt;&lt;/span&gt;
&lt;a href="#cve-v5-import-and-indexing-enhancements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Added CVE v5 NDJSON rank importer.&lt;/li&gt;
&lt;li&gt;Added support for handling incomplete or multiline NDJSON records in &lt;code&gt;CVEListV5Handler&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Introduced optional CVE v5 word indexing.&lt;/li&gt;
&lt;li&gt;Added missing-word tracking for CVE v5 imports.&lt;/li&gt;
&lt;li&gt;Split missing-word tracking into separate vendor and product sets for more precise analysis.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Faster and more flexible CPE imports&lt;span class="hx:absolute hx:-mt-20" id="faster-and-more-flexible-cpe-imports"&gt;&lt;/span&gt;
&lt;a href="#faster-and-more-flexible-cpe-imports" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Parallelized NVD CPE imports for improved performance.&lt;/li&gt;
&lt;li&gt;Refactored import logic into reusable handler classes.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;NVDCPEHandler&lt;/code&gt; for importing the NVD CPE Dictionary 2.0 JSON format.&lt;/li&gt;
&lt;li&gt;Extended import support for tar archives and standalone JSON files.&lt;/li&gt;
&lt;li&gt;Continued support for legacy XML imports through &lt;code&gt;XMLCPEHandler&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added logging of JSON file names found inside tar archives.&lt;/li&gt;
&lt;li&gt;Expanded the import model so cpe-guesser can integrate CPE data from additional sources, including Vulnerability-Lookup dumps, instead of relying solely on NVD feeds.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Configuration and deployment improvements&lt;span class="hx:absolute hx:-mt-20" id="configuration-and-deployment-improvements"&gt;&lt;/span&gt;
&lt;a href="#configuration-and-deployment-improvements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Improved configuration robustness by embedding default settings in code when configuration is missing or incomplete.&lt;/li&gt;
&lt;li&gt;Made the Valkey database number configurable.&lt;/li&gt;
&lt;li&gt;Fixed Docker deployment and &lt;code&gt;docker-compose&lt;/code&gt; configuration to use Valkey correctly.&lt;/li&gt;
&lt;li&gt;Corrected &lt;code&gt;settings.yaml&lt;/code&gt; structure issues.&lt;/li&gt;
&lt;li&gt;Added missing requirements and improved script executability in &lt;code&gt;bin/&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Documentation and maintenance&lt;span class="hx:absolute hx:-mt-20" id="documentation-and-maintenance"&gt;&lt;/span&gt;
&lt;a href="#documentation-and-maintenance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Updated README documentation.&lt;/li&gt;
&lt;li&gt;Added examples for the JSON format while keeping legacy format examples.&lt;/li&gt;
&lt;li&gt;Applied Black formatting across library code and regression/import tests.&lt;/li&gt;
&lt;li&gt;General linting and formatting cleanups.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Breaking / notable changes&lt;span class="hx:absolute hx:-mt-20" id="breaking--notable-changes"&gt;&lt;/span&gt;
&lt;a href="#breaking--notable-changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;The project now defaults to the &lt;strong&gt;CPE Dictionary 2.0&lt;/strong&gt; feed.&lt;/li&gt;
&lt;li&gt;Import handling has been refactored significantly around dedicated handler classes.&lt;/li&gt;
&lt;li&gt;CLI import behavior was simplified by removing the redundant &lt;code&gt;--update&lt;/code&gt; flag and improving boolean toggle handling.&lt;/li&gt;
&lt;li&gt;The project architecture is now better suited for &lt;strong&gt;multi-source CPE ingestion&lt;/strong&gt;, reducing dependence on NVD as the single upstream source.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Contributors&lt;span class="hx:absolute hx:-mt-20" id="contributors"&gt;&lt;/span&gt;
&lt;a href="#contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thanks to everyone who contributed to this release, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Alexandre Dulaunoy&lt;/li&gt;
&lt;li&gt;Esa Jokinen&lt;/li&gt;
&lt;li&gt;Surya Kanagasabapathy&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upgrade notes&lt;span class="hx:absolute hx:-mt-20" id="upgrade-notes"&gt;&lt;/span&gt;
&lt;a href="#upgrade-notes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;When upgrading to 2.0, review:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Your import workflows, especially if you rely on legacy XML-only behavior.&lt;/li&gt;
&lt;li&gt;Your configuration files, although defaults now make startup more robust.&lt;/li&gt;
&lt;li&gt;Your Docker and Valkey setup if you deploy with containers.&lt;/li&gt;
&lt;li&gt;Your data ingestion pipeline if you want to take advantage of alternative CPE sources such as the Vulnerability-Lookup dumps.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Summary&lt;span class="hx:absolute hx:-mt-20" id="summary"&gt;&lt;/span&gt;
&lt;a href="#summary" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;cpe-guesser 2.0 is a substantial release that modernizes the import pipeline, adds support for current NVD CPE data formats, improves ranking quality, and makes deployments more robust and scalable. It also opens the door to a more autonomous and flexible ingestion model by supporting additional CPE sources beyond NVD.&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 4.2.0 released</title><link>http://www.vulnerability-lookup.org/2026/03/20/vulnerability-lookup-4-2-0/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/03/20/vulnerability-lookup-4-2-0/</guid><description>
&lt;p&gt;It is our honour to announce the release of &lt;strong&gt;Vulnerability-Lookup 4.2.0&lt;/strong&gt;!&lt;br&gt;
This version brings a large number of new CSAF-based vulnerability advisory sources, improvements to the web interface, and several bug fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;New CSAF-based sources&lt;span class="hx:absolute hx:-mt-20" id="new-csaf-based-sources"&gt;&lt;/span&gt;
&lt;a href="#new-csaf-based-sources" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/new-sources-menu-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/new-sources-menu-1.png" alt="New sources menu folded" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/new-sources-menu-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/new-sources-menu-2.png" alt="New sources menu unfolded" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As the number of GNA keeps growing and the interest around the &lt;a href="https://gcve.eu"target="_blank" rel="noopener"&gt;GCVE-EU initiative&lt;/a&gt; increases, these UI improvements and filtering
capabilities are becoming essential to efficiently explore the various available sources.&lt;/p&gt;
&lt;p&gt;Below is the list of CSAF-based sources available by default. You can enable or disable each feeder via the
&lt;code&gt;config/modules.cfg&lt;/code&gt; configuration file. The display in the web interface is also configurable through the
&lt;code&gt;config/website.py&lt;/code&gt; configuration file.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://global.abb/group/en/technology/cyber-security/alerts-and-notifications"target="_blank" rel="noopener"&gt;ABB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ads-tec-iit.com"target="_blank" rel="noopener"&gt;ads-tec Industrial IT GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://auma.com"target="_blank" rel="noopener"&gt;AUMA Riester GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.beckhoff.com"target="_blank" rel="noopener"&gt;Beckhoff Automation GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.bender.de"target="_blank" rel="noopener"&gt;Bender GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.gavazziautomation.com"target="_blank" rel="noopener"&gt;Carlo Gavazzi Automation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://wid.cert-bund.de/portal/wid/start"target="_blank" rel="noopener"&gt;CERT-Bund&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://certvde.com"target="_blank" rel="noopener"&gt;CERT@VDE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"target="_blank" rel="noopener"&gt;CISA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cisco.com"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.codesys.com"target="_blank" rel="noopener"&gt;CODESYS GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.endress.com"target="_blank" rel="noopener"&gt;Endress+Hauser AG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.festo.com"target="_blank" rel="noopener"&gt;Festo SE &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.frauscher.com"target="_blank" rel="noopener"&gt;Frauscher Sensortechnik GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.helmholz.de"target="_blank" rel="noopener"&gt;Helmholz GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.hima.com"target="_blank" rel="noopener"&gt;HIMA Paul Hildebrandt GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ifm.com"target="_blank" rel="noopener"&gt;ifm electronic GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.janitza.com"target="_blank" rel="noopener"&gt;Janitza electronics GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.lenze.com"target="_blank" rel="noopener"&gt;Lenze SE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://mbconnectline.com"target="_blank" rel="noopener"&gt;MB connect line GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.mt.com"target="_blank" rel="noopener"&gt;Mettler-Toledo GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://msrc.microsoft.com"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.miele.com"target="_blank" rel="noopener"&gt;Miele &amp;amp; Cie KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://murrelektronik.com"target="_blank" rel="noopener"&gt;Murrelektronik GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://advisories.ncsc.nl"target="_blank" rel="noopener"&gt;NCSC-NL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://security.nozominetworks.com"target="_blank" rel="noopener"&gt;Nozomi Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.open-xchange.com"target="_blank" rel="noopener"&gt;Open-Xchange&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.suse.com/support/security/"target="_blank" rel="noopener"&gt;OpenSuse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pepperl-fuchs.com"target="_blank" rel="noopener"&gt;Pepperl+Fuchs SE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://phoenixcontact.com/psirt"target="_blank" rel="noopener"&gt;Phoenix Contact GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pilz.com"target="_blank" rel="noopener"&gt;Pilz GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://access.redhat.com/security/"target="_blank" rel="noopener"&gt;Red Hat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.sauter-controls.com"target="_blank" rel="noopener"&gt;Sauter AG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.se.com/ww/en/work/support/cybersecurity/vulnerability-policy/"target="_blank" rel="noopener"&gt;Schneider Electric&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.sick.com/psirt"target="_blank" rel="noopener"&gt;Sick&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.siemens.com/global/en/products/services/cert.html"target="_blank" rel="noopener"&gt;Siemens&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sma.de"target="_blank" rel="noopener"&gt;SMA Solar Technology AG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.suse.com/support/security/"target="_blank" rel="noopener"&gt;Suse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swarco.de"target="_blank" rel="noopener"&gt;SWARCO TRAFFIC SYSTEMS GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.trumpf.com"target="_blank" rel="noopener"&gt;Trumpf SE + Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://varta-storage.com"target="_blank" rel="noopener"&gt;VARTA Storage GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.wago.com/psirt"target="_blank" rel="noopener"&gt;WAGO GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.weidmueller.com"target="_blank" rel="noopener"&gt;Weidmueller Interface GmbH &amp;amp; Co. KG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://welotec.com"target="_blank" rel="noopener"&gt;Welotec GmbH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.wut.de"target="_blank" rel="noopener"&gt;Wiesemann &amp;amp; Theis GmbH&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Improvements&lt;span class="hx:absolute hx:-mt-20" id="improvements"&gt;&lt;/span&gt;
&lt;a href="#improvements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/improved-csaf-view.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/improved-csaf-view.png" alt="Improved CSAF view" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Enriched CSAF view&lt;/strong&gt;&lt;br&gt;
The generic CSAF view now includes severity, vulnerabilities, references, and acknowledgments.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d528da8"target="_blank" rel="noopener"&gt;d528da8&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Enriched OSV view&lt;/strong&gt;&lt;br&gt;
Added severity and references to the generic OSV view.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/65de73e"target="_blank" rel="noopener"&gt;65de73e&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Date published in CVE records&lt;/strong&gt;&lt;br&gt;
If known, the &lt;code&gt;datePublic&lt;/code&gt; field of CVE records is now displayed.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/861a082"target="_blank" rel="noopener"&gt;861a082&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Boost recent sightings enabled by default&lt;/strong&gt;&lt;br&gt;
The boost recent sightings switch is now checked by default.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/4eed4c4"target="_blank" rel="noopener"&gt;4eed4c4&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;New source argument for the full-text indexer&lt;/strong&gt;&lt;br&gt;
Added a &lt;code&gt;source&lt;/code&gt; argument to the indexer for more targeted indexing.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d4e6e1f"target="_blank" rel="noopener"&gt;d4e6e1f&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Less verbose indexing&lt;/strong&gt;&lt;br&gt;
Reduced the verbosity of the full-text search indexing process.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a563dff"target="_blank" rel="noopener"&gt;a563dff&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Configuration improvements&lt;/strong&gt;&lt;br&gt;
Reorganized the default &lt;code&gt;SOURCES_TO_SHOW&lt;/code&gt; config variable and updated the sample &lt;code&gt;website.py&lt;/code&gt; configuration with examples for the new configuration options.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f699400"target="_blank" rel="noopener"&gt;f699400&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/6e8fb6c"target="_blank" rel="noopener"&gt;6e8fb6c&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Documentation updates&lt;/strong&gt;&lt;br&gt;
Various improvements to the documentation, including GCVE publication as a GNA and Known Exploited Vulnerabilities Catalogs.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/58a4d83"target="_blank" rel="noopener"&gt;58a4d83&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/143f5f5"target="_blank" rel="noopener"&gt;143f5f5&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1f6d6d3"target="_blank" rel="noopener"&gt;1f6d6d3&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/52c774f"target="_blank" rel="noopener"&gt;52c774f&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Updated Python dependencies&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/6e30dc2"target="_blank" rel="noopener"&gt;6e30dc2&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Fixed incorrect vulnerability ID passed in various Jinja macros.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/cf1b209"target="_blank" rel="noopener"&gt;cf1b209&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fixed the default product option so the form correctly re-submits its value when changing sort/order controls.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7373f8f"target="_blank" rel="noopener"&gt;7373f8f&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Suppressed spurious config warnings for disabled features.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/c82e911"target="_blank" rel="noopener"&gt;c82e911&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fixed a variable shadowing issue in &lt;code&gt;parse_vuln_payload()&lt;/code&gt; where the local &lt;code&gt;source&lt;/code&gt; variable was overriding the function parameter.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/cb03721"target="_blank" rel="noopener"&gt;cb03721&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.2.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.2.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you to all contributors and testers!&lt;/p&gt;
&lt;p&gt;Special thanks to &lt;a href="https://github.com/Rafiot/"target="_blank" rel="noopener"&gt;Raphaël Vinot&lt;/a&gt; for adding the new sources.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real-time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 4.1.0 released</title><link>http://www.vulnerability-lookup.org/2026/03/10/vulnerability-lookup-4-1-0/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/03/10/vulnerability-lookup-4-1-0/</guid><description>
&lt;p&gt;We are excited to announce the release of &lt;strong&gt;Vulnerability-Lookup 4.1.0&lt;/strong&gt;!&lt;br&gt;
This version brings new features, improvements, and several bug fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Full-text search with Meilisearch&lt;span class="hx:absolute hx:-mt-20" id="full-text-search-with-meilisearch"&gt;&lt;/span&gt;
&lt;a href="#full-text-search-with-meilisearch" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;You can now enable full-text search on your Vulnerability-Lookup instance. This new feature relies on &lt;a href="https://www.meilisearch.com/"target="_blank" rel="noopener"&gt;Meilisearch&lt;/a&gt; and the Vulnerability-Lookup event-stream. The indexer subscribes to the appropriate topic and receives all new and updated vulnerabilities pushed through the Valkey event-stream. This is the event-stream used by &lt;a href="https://github.com/vulnerability-lookup/FediVuln"target="_blank" rel="noopener"&gt;FediVuln&lt;/a&gt; in order to push notifications from a Vulnerability-Lookup instance to the Fediverse.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/meilisearch-pub-sub.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/meilisearch-pub-sub.png" alt="Meilisearch pub/sub architecture" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A documentation &lt;a href="https://www.vulnerability-lookup.org/documentation/fulltextsearch.html"target="_blank" rel="noopener"&gt;is available&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-product.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-product.png" alt="Full-text search by product" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-cvss.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-cvss.png" alt="Full-text search by CVSS" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-commit-id.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-commit-id.png" alt="Full-text search by commit ID" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-indexer-monitoring.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-indexer-monitoring.png" alt="Full-text indexer monitoring" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;New full-text search API endpoint&lt;span class="hx:absolute hx:-mt-20" id="new-full-text-search-api-endpoint"&gt;&lt;/span&gt;
&lt;a href="#new-full-text-search-api-endpoint" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;A new endpoint at &lt;code&gt;/api/vulnerability/fulltext&lt;/code&gt; is now available for programmatic full-text searches.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9cdac1cce7ad0fb11bf1a49a8d40d4e9a5035bb5"target="_blank" rel="noopener"&gt;9cdac1c&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-API.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/fulltext-search-API.png" alt="Full-text search API" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Better monitoring for email notifications&lt;span class="hx:absolute hx:-mt-20" id="better-monitoring-for-email-notifications"&gt;&lt;/span&gt;
&lt;a href="#better-monitoring-for-email-notifications" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Email notifications are now monitored using Valkey.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7e3c26f85656174999fe2cc982c0493250383328"target="_blank" rel="noopener"&gt;7e3c26f&lt;/a&gt;)&lt;/p&gt;
&lt;h3&gt;New importers for Haskell, OCaml, and AlmaLinux&lt;span class="hx:absolute hx:-mt-20" id="new-importers-for-haskell-ocaml-and-almalinux"&gt;&lt;/span&gt;
&lt;a href="#new-importers-for-haskell-ocaml-and-almalinux" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;You can now import vulnerabilities from three additional ecosystems:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Haskell&lt;/strong&gt; – &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d4ddbe9b4e7a9be12ee03a56ebe5321fb1b322fb"target="_blank" rel="noopener"&gt;d4ddbe9&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;OCaml&lt;/strong&gt; – &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3596b7348006f66e817c1adc3c61d9c96ce678d3"target="_blank" rel="noopener"&gt;3596b73&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AlmaLinux&lt;/strong&gt; – A new feeder to automatically gather AlmaLinux vulnerabilities. &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3e23c53e258e1f557b681de45958c068bbbb6f4e"target="_blank" rel="noopener"&gt;3e23c53&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/new-sources.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/new-sources.png" alt="New sources" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Sightings table recency boost&lt;span class="hx:absolute hx:-mt-20" id="sightings-table-recency-boost"&gt;&lt;/span&gt;
&lt;a href="#sightings-table-recency-boost" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;You can now toggle a &amp;ldquo;recency boost&amp;rdquo; in the sightings table to highlight the latest vulnerability activity.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e966a70be3288e9433eff3bed441a2ad42ff0828"target="_blank" rel="noopener"&gt;e966a70&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/sightings-boost.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/sightings-boost.png" alt="Sightings recency boost" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Improvements&lt;span class="hx:absolute hx:-mt-20" id="improvements"&gt;&lt;/span&gt;
&lt;a href="#improvements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Streamlined admin interface for users and bundles for a more consistent experience.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2b1cc875b8a701858dec80a3bdaa835f0cdb18da"target="_blank" rel="noopener"&gt;2b1cc87&lt;/a&gt; | &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/20912aca6453980513dd4c871e5d997acaacfd77"target="_blank" rel="noopener"&gt;20912ac&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Adjusted how recent sightings are weighted to better reflect activity trends.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a8dc7f307a1924343806d4d8ef0174c2c9f185af"target="_blank" rel="noopener"&gt;a8dc7f3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Improved stability in real-time streams and email notifications.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/95c249a8e535728790435fe5354841542cd97d18"target="_blank" rel="noopener"&gt;95c249a&lt;/a&gt; | &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/fdf1a2f29266f81bceff29ec578dc33614defb55"target="_blank" rel="noopener"&gt;fdf1a2f&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Corrected pagination and comment display in the API.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/6003ad11ad4286e0037335e9d30fc9eb17447063"target="_blank" rel="noopener"&gt;6003ad1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fixed issues with sending emails when templates failed and case-sensitive IDs in certain feeds.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7f972226f5266d3201a82f71e83abd39d10cc4c1"target="_blank" rel="noopener"&gt;7f97222&lt;/a&gt; | &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d87cc4673a1b777eef7f04c4b2909cda895f9059"target="_blank" rel="noopener"&gt;d87cc46&lt;/a&gt; | &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/bf0b8bacdc1bd115d9d6f6823790a229c1c57839"target="_blank" rel="noopener"&gt;bf0b8ba&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.1.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.1.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you to all contributors and testers!
Escpecially to &lt;a href="https://github.com/NMD03"target="_blank" rel="noopener"&gt;Niclas Dauster&lt;/a&gt; for the full-text search feature. And to &lt;a href="https://github.com/Rafiot/"target="_blank" rel="noopener"&gt;Raphaël Vinot&lt;/a&gt; for the new sources.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - February 2026</title><link>http://www.vulnerability-lookup.org/2026/03/02/vulnerability-report-february-2026/</link><pubDate>Mon, 02 Mar 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/03/02/vulnerability-report-february-2026/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for February 2026, based on sightings collected from various sources,
including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, &lt;a href="https://github.com/rapid7/metasploit-framework"target="_blank" rel="noopener"&gt;Metasploit&lt;/a&gt;, and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;February 2026 was led by &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1731"target="_blank" rel="noopener"&gt;CVE-2026-1731&lt;/a&gt;, a Critical-severity issue affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA), with 158 sightings. It was followed closely by &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-2441"target="_blank" rel="noopener"&gt;CVE-2026-2441&lt;/a&gt; in Google Chrome with 143 sightings.&lt;/p&gt;
&lt;p&gt;Microsoft-related vulnerabilities were also prominent in the top 10, including &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20841"target="_blank" rel="noopener"&gt;CVE-2026-20841&lt;/a&gt; (Windows Notepad) and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21509"target="_blank" rel="noopener"&gt;CVE-2026-21509&lt;/a&gt; (Microsoft 365 Apps for Enterprise). Other heavily sighted entries spanned enterprise recovery and networking products such as Dell RecoverPoint for Virtual Machines (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-22769"target="_blank" rel="noopener"&gt;CVE-2026-22769&lt;/a&gt;) and Cisco Catalyst SD-WAN Manager (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20127"target="_blank" rel="noopener"&gt;CVE-2026-20127&lt;/a&gt;), as well as platform and tooling ecosystems like Apple macOS (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20700"target="_blank" rel="noopener"&gt;CVE-2026-20700&lt;/a&gt;), Ivanti Endpoint Manager Mobile (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1281"target="_blank" rel="noopener"&gt;CVE-2026-1281&lt;/a&gt;), and n8n (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-25049"target="_blank" rel="noopener"&gt;CVE-2026-25049&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;February continued to be an active month for known exploited vulnerabilities. The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; added 28 new entries during the month. Notable additions include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1731"target="_blank" rel="noopener"&gt;CVE-2026-1731&lt;/a&gt;: BeyondTrust Remote Support (RS) &amp;amp; Privileged Remote Access (PRA)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-2441"target="_blank" rel="noopener"&gt;CVE-2026-2441&lt;/a&gt;: Google Chrome&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20127"target="_blank" rel="noopener"&gt;CVE-2026-20127&lt;/a&gt;: Cisco Catalyst SD-WAN Manager&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-22769"target="_blank" rel="noopener"&gt;CVE-2026-22769&lt;/a&gt;: Dell RecoverPoint for Virtual Machines&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49113"target="_blank" rel="noopener"&gt;CVE-2025-49113&lt;/a&gt;: Roundcube Webmail&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-7796"target="_blank" rel="noopener"&gt;CVE-2020-7796&lt;/a&gt;: synacor zimbra_collaboration_suite&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;CIRCL Known Exploited Vulnerabilities catalog&lt;/a&gt; added three entries (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-25108"target="_blank" rel="noopener"&gt;CVE-2026-25108&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1340"target="_blank" rel="noopener"&gt;CVE-2026-1340&lt;/a&gt;, and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1281"target="_blank" rel="noopener"&gt;CVE-2026-1281&lt;/a&gt;), while the &lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;ENISA KEV catalog&lt;/a&gt; had no new entries in February.&lt;/p&gt;
&lt;p&gt;The Ghost CVE Report highlights eight vulnerability identifiers that were observed in sightings despite limited or missing public records. The most frequently sighted were &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt; (5 occurrences) and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1584#sightings"target="_blank" rel="noopener"&gt;CVE-2026-1584&lt;/a&gt; (4 occurrences), followed by &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23456#sightings"target="_blank" rel="noopener"&gt;CVE-2026-23456&lt;/a&gt; (3 occurrences).&lt;/p&gt;
&lt;p&gt;Contributor insights this month covered Cisco Catalyst SD-WAN vulnerabilities, an IceWarp command-injection RCE, analysis of CVEs affecting the Svelte ecosystem, TP-Link VIGI IP camera issues, and reporting on UAC-0001 (APT28) activity leveraging &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21509"target="_blank" rel="noopener"&gt;CVE-2026-21509&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Top 10 Vendors of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/top-10-vendors.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/top-10-vendors.png" alt="Top 10 Vendors of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 Assigners of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-assigners-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-assigners-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/03/top-10-assigners.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/top-10-assigners.png" alt="Top 10 Assigners of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1731"target="_blank" rel="noopener"&gt;CVE-2026-1731&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;158&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=BeyondTrust"target="_blank" rel="noopener"&gt;BeyondTrust&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=BeyondTrust&amp;amp;product=Remote&amp;#43;Support%28RS%29&amp;#43;%26&amp;#43;Privileged&amp;#43;Remote&amp;#43;Access%28PRA%29"target="_blank" rel="noopener"&gt;Remote Support(RS) &amp;amp; Privileged Remote Access(PRA)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9914)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-2441"target="_blank" rel="noopener"&gt;CVE-2026-2441&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;143&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9908)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20841"target="_blank" rel="noopener"&gt;CVE-2026-20841&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;131&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;Notepad"target="_blank" rel="noopener"&gt;Windows Notepad&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9833)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21509"target="_blank" rel="noopener"&gt;CVE-2026-21509&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;113&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;365&amp;#43;Apps&amp;#43;for&amp;#43;Enterprise"target="_blank" rel="noopener"&gt;Microsoft 365 Apps for Enterprise&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9687)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-22769"target="_blank" rel="noopener"&gt;CVE-2026-22769&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;91&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dell"target="_blank" rel="noopener"&gt;Dell&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dell&amp;amp;product=RecoverPoint&amp;#43;for&amp;#43;Virtual&amp;#43;Machines"target="_blank" rel="noopener"&gt;RecoverPoint for Virtual Machines&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9356)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20127"target="_blank" rel="noopener"&gt;CVE-2026-20127&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;76&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN&amp;#43;Manager"target="_blank" rel="noopener"&gt;Cisco Catalyst SD-WAN Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9411)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20700"target="_blank" rel="noopener"&gt;CVE-2026-20700&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;69&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=macOS"target="_blank" rel="noopener"&gt;macOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9705)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1281"target="_blank" rel="noopener"&gt;CVE-2026-1281&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;69&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint&amp;#43;Manager&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9791)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-25253"target="_blank" rel="noopener"&gt;CVE-2026-25253&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;55&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=OpenClaw"target="_blank" rel="noopener"&gt;OpenClaw&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=OpenClaw&amp;amp;product=OpenClaw"target="_blank" rel="noopener"&gt;OpenClaw&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7975)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-25049"target="_blank" rel="noopener"&gt;CVE-2026-25049&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;54&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=n8n-io"target="_blank" rel="noopener"&gt;n8n-io&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=n8n-io&amp;amp;product=n8n"target="_blank" rel="noopener"&gt;n8n&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.617)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20127"target="_blank" rel="noopener"&gt;CVE-2026-20127&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN&amp;#43;Manager"target="_blank" rel="noopener"&gt;Cisco Catalyst SD-WAN Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9183)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-20775"target="_blank" rel="noopener"&gt;CVE-2022-20775&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Catalyst&amp;#43;SD-WAN"target="_blank" rel="noopener"&gt;Cisco Catalyst SD-WAN&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9894)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-25108"target="_blank" rel="noopener"&gt;CVE-2026-25108&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-24&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Soliton&amp;#43;Systems&amp;#43;K.K."target="_blank" rel="noopener"&gt;Soliton Systems K.K.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Soliton&amp;#43;Systems&amp;#43;K.K.&amp;amp;product=FileZen"target="_blank" rel="noopener"&gt;FileZen&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8244)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49113"target="_blank" rel="noopener"&gt;CVE-2025-49113&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube"target="_blank" rel="noopener"&gt;Roundcube&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube&amp;amp;product=Webmail"target="_blank" rel="noopener"&gt;Webmail&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7952)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-68461"target="_blank" rel="noopener"&gt;CVE-2025-68461&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-20&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube"target="_blank" rel="noopener"&gt;Roundcube&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube&amp;amp;product=Webmail"target="_blank" rel="noopener"&gt;Webmail&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9892)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-22175"target="_blank" rel="noopener"&gt;CVE-2021-22175&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-18&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GitLab"target="_blank" rel="noopener"&gt;GitLab&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GitLab&amp;amp;product=GitLab"target="_blank" rel="noopener"&gt;GitLab&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.7533)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-22769"target="_blank" rel="noopener"&gt;CVE-2026-22769&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-18&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dell"target="_blank" rel="noopener"&gt;Dell&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dell&amp;amp;product=RecoverPoint&amp;#43;for&amp;#43;Virtual&amp;#43;Machines"target="_blank" rel="noopener"&gt;RecoverPoint for Virtual Machines&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9356)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-7796"target="_blank" rel="noopener"&gt;CVE-2020-7796&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-17&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=synacor"target="_blank" rel="noopener"&gt;synacor&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=synacor&amp;amp;product=zimbra_collaboration_suite"target="_blank" rel="noopener"&gt;zimbra_collaboration_suite&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.5846)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-7694"target="_blank" rel="noopener"&gt;CVE-2024-7694&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-17&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TeamT5"target="_blank" rel="noopener"&gt;TeamT5&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TeamT5&amp;amp;product=ThreatSonar&amp;#43;Anti-Ransomware"target="_blank" rel="noopener"&gt;ThreatSonar Anti-Ransomware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9626)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2008-0015"target="_blank" rel="noopener"&gt;CVE-2008-0015&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-17&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows"target="_blank" rel="noopener"&gt;Windows&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.981)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-2441"target="_blank" rel="noopener"&gt;CVE-2026-2441&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-17&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9908)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1731"target="_blank" rel="noopener"&gt;CVE-2026-1731&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=BeyondTrust"target="_blank" rel="noopener"&gt;BeyondTrust&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=BeyondTrust&amp;amp;product=Remote&amp;#43;Support%28RS%29&amp;#43;%26&amp;#43;Privileged&amp;#43;Remote&amp;#43;Access%28PRA%29"target="_blank" rel="noopener"&gt;Remote Support(RS) &amp;amp; Privileged Remote Access(PRA)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9914)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-15556"target="_blank" rel="noopener"&gt;CVE-2025-15556&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=notepad-plus-plus"target="_blank" rel="noopener"&gt;notepad-plus-plus&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=notepad-plus-plus&amp;amp;product=notepad-plus-plus"target="_blank" rel="noopener"&gt;notepad-plus-plus&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9083)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20700"target="_blank" rel="noopener"&gt;CVE-2026-20700&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=macOS"target="_blank" rel="noopener"&gt;MacOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9705)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-43468"target="_blank" rel="noopener"&gt;CVE-2024-43468&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Configuration&amp;#43;Manager"target="_blank" rel="noopener"&gt;Microsoft Configuration Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8181)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-40536"target="_blank" rel="noopener"&gt;CVE-2025-40536&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SolarWinds"target="_blank" rel="noopener"&gt;SolarWinds&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SolarWinds&amp;amp;product=Web&amp;#43;Help&amp;#43;Desk"target="_blank" rel="noopener"&gt;Web Help Desk&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7215)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21533"target="_blank" rel="noopener"&gt;CVE-2026-21533&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-10&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1607"target="_blank" rel="noopener"&gt;Windows 10 Version 1607&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9889)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21510"target="_blank" rel="noopener"&gt;CVE-2026-21510&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-10&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1607"target="_blank" rel="noopener"&gt;Windows 10 Version 1607&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5272)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21513"target="_blank" rel="noopener"&gt;CVE-2026-21513&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-10&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1607"target="_blank" rel="noopener"&gt;Windows 10 Version 1607&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8378)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21514"target="_blank" rel="noopener"&gt;CVE-2026-21514&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-10&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;365&amp;#43;Apps&amp;#43;for&amp;#43;Enterprise"target="_blank" rel="noopener"&gt;Microsoft 365 Apps for Enterprise&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9769)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21519"target="_blank" rel="noopener"&gt;CVE-2026-21519&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-10&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1607"target="_blank" rel="noopener"&gt;Windows 10 Version 1607&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9183)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21525"target="_blank" rel="noopener"&gt;CVE-2026-21525&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-10&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1607"target="_blank" rel="noopener"&gt;Windows 10 Version 1607&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9918)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24423"target="_blank" rel="noopener"&gt;CVE-2026-24423&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-05&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SmarterTools"target="_blank" rel="noopener"&gt;SmarterTools&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SmarterTools&amp;amp;product=SmarterMail"target="_blank" rel="noopener"&gt;SmarterMail&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9798)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11953"target="_blank" rel="noopener"&gt;CVE-2025-11953&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-05&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=react-native-community"target="_blank" rel="noopener"&gt;react-native-community&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=react-native-community&amp;amp;product=react_native_community_cli"target="_blank" rel="noopener"&gt;react_native_community_cli&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.987)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-19006"target="_blank" rel="noopener"&gt;CVE-2019-19006&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sangoma"target="_blank" rel="noopener"&gt;sangoma&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sangoma&amp;amp;product=freepbx"target="_blank" rel="noopener"&gt;freepbx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.6005)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-64328"target="_blank" rel="noopener"&gt;CVE-2025-64328&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=FreePBX"target="_blank" rel="noopener"&gt;FreePBX&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=FreePBX&amp;amp;product=filestore"target="_blank" rel="noopener"&gt;filestore&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7976)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-39935"target="_blank" rel="noopener"&gt;CVE-2021-39935&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GitLab"target="_blank" rel="noopener"&gt;GitLab&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GitLab&amp;amp;product=GitLab"target="_blank" rel="noopener"&gt;GitLab&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.8559)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-40551"target="_blank" rel="noopener"&gt;CVE-2025-40551&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SolarWinds"target="_blank" rel="noopener"&gt;SolarWinds&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SolarWinds&amp;amp;product=Web&amp;#43;Help&amp;#43;Desk"target="_blank" rel="noopener"&gt;Web Help Desk&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9385)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=405284c2-e461-4670-8979-7fd2c9755a60"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CISA Catalog.&lt;/p&gt;
&lt;h3&gt;CIRCL&lt;span class="hx:absolute hx:-mt-20" id="circl"&gt;&lt;/span&gt;
&lt;a href="#circl" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-25108"target="_blank" rel="noopener"&gt;CVE-2026-25108&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Soliton&amp;#43;Systems&amp;#43;K.K."target="_blank" rel="noopener"&gt;Soliton Systems K.K.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Soliton&amp;#43;Systems&amp;#43;K.K.&amp;amp;product=FileZen"target="_blank" rel="noopener"&gt;FileZen&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8244)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1340"target="_blank" rel="noopener"&gt;CVE-2026-1340&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint&amp;#43;Manager&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9791)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1281"target="_blank" rel="noopener"&gt;CVE-2026-1281&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-02-03&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint&amp;#43;Manager&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9791)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=1a89b78e-f703-45f3-bb86-59eb712668bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the CIRCL Catalog.&lt;/p&gt;
&lt;h3&gt;ENISA&lt;span class="hx:absolute hx:-mt-20" id="enisa"&gt;&lt;/span&gt;
&lt;a href="#enisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;No new entry in February.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?catalog_uuid=cce329bf-df49-4c6e-a027-80be2e6483bd"target="_blank" rel="noopener"&gt;More KEV entries&lt;/a&gt; from the ENISA Catalog.&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2026&amp;amp;month=02"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/03/top-10-weaknesses.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Click the image for more information.&lt;/p&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;Sightings detected between 2026-02-01 and 2026-02-28 that are associated with vulnerabilities without public records.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th style="text-align: right"&gt;Occurrences&lt;/th&gt;
&lt;th&gt;Comment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;5&lt;/td&gt;
&lt;td&gt;OpenCMS Unauthenticated XXE Vulnerability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1584#sightings"target="_blank" rel="noopener"&gt;CVE-2026-1584&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;4&lt;/td&gt;
&lt;td&gt;libgnutls: Fix NULL pointer dereference in PSK binder verification&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23456#sightings"target="_blank" rel="noopener"&gt;CVE-2026-23456&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;3&lt;/td&gt;
&lt;td&gt;YoSmart YoLink Smart Hub&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-15576#sightings"target="_blank" rel="noopener"&gt;CVE-2025-15576&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;FreeBSD 14.3 and 13.5 (Jail chroot escape via fd exchange with a different jail)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-3038#sightings"target="_blank" rel="noopener"&gt;CVE-2026-3038&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;All supported versions of FreeBSD (Local DoS and possible privilege escalation via routing sockets)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13050#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13050&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0221/"target="_blank" rel="noopener"&gt;Multiple vulnerabilities in Centreon products&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12523#sightings"target="_blank" rel="noopener"&gt;CVE-2025-12523&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0221/"target="_blank" rel="noopener"&gt;Multiple vulnerabilities in Centreon products&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-71210#sightings"target="_blank" rel="noopener"&gt;CVE-2025-71210&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://success.trendmicro.com/en-US/solution/KA-0022458"target="_blank" rel="noopener"&gt;Multiple vulnerabilities in Trend Micro products (KA-0022458)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/b24f0b20-207c-4881-af91-eb1d15b224ba"target="_blank" rel="noopener"&gt;Cisco Catalyst SD-WAN Vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/7ce61e2c-9493-44fb-8892-81a7187f8142"target="_blank" rel="noopener"&gt;IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/42521e67-5c8d-4b16-a114-e0db686c91a7"target="_blank" rel="noopener"&gt;MajorDoMo Revisited: What I Missed in 2023&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/2b58b75c-ed2f-43e6-9955-22f649ee1814"target="_blank" rel="noopener"&gt;CVEs affecting the Svelte ecosystem&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/e651be34-b4db-4d9d-a746-15699bfe7264"target="_blank" rel="noopener"&gt;TP-Link Systems Inc. VIGI Series IP Camera&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/10eccd79-ce3d-4273-b399-d535e160f2c9"target="_blank" rel="noopener"&gt;UAC-0001 (APT28) carries out cyberattacks against Ukraine and EU countries using the exploit CVE-2026-21509&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - January 2026</title><link>http://www.vulnerability-lookup.org/2026/02/18/vulnerability-report-january-2026/</link><pubDate>Wed, 18 Feb 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/02/18/vulnerability-report-january-2026/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for January 2026, based on sightings collected from various sources,
including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, &lt;a href="https://github.com/rapid7/metasploit-framework"target="_blank" rel="noopener"&gt;Metasploit&lt;/a&gt;, and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;January 2026 saw two vulnerabilities tied for most frequently sighted with 110 sightings each: &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21858"target="_blank" rel="noopener"&gt;CVE-2026-21858&lt;/a&gt;, a Critical-severity vulnerability in n8n-io&amp;rsquo;s n8n workflow automation platform, and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24061"target="_blank" rel="noopener"&gt;CVE-2026-24061&lt;/a&gt;, a Critical vulnerability affecting GNU Inetutils. The n8n vulnerability was extensively covered in contributor insights, notably in &lt;a href="https://vulnerability.circl.lu/comment/d766d344-c029-419a-b990-fb512e9cb929"target="_blank" rel="noopener"&gt;&amp;ldquo;The Ni8mare Test: n8n RCE Under the Microscope&amp;rdquo;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Other critical vulnerabilities in the top 10 include &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt; in Meta&amp;rsquo;s react-server-dom-webpack (97 sightings), &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20045"target="_blank" rel="noopener"&gt;CVE-2026-20045&lt;/a&gt; in Cisco Unified Communications Manager (80 sightings), &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24858"target="_blank" rel="noopener"&gt;CVE-2026-24858&lt;/a&gt; in Fortinet FortiManager (80 sightings), &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1281"target="_blank" rel="noopener"&gt;CVE-2026-1281&lt;/a&gt; in Ivanti Endpoint Manager Mobile (70 sightings), and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;, an older but still active vulnerability in billion 5200w-t devices (62 sightings).&lt;/p&gt;
&lt;p&gt;January was a busy month for actively exploited vulnerabilities, with 15 new entries added to the CISA Known Exploited Vulnerabilities catalog. Notable additions include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24858"target="_blank" rel="noopener"&gt;CVE-2026-24858&lt;/a&gt;: Fortinet FortiManager (Critical severity)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21509"target="_blank" rel="noopener"&gt;CVE-2026-21509&lt;/a&gt; and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24061"target="_blank" rel="noopener"&gt;CVE-2026-24061&lt;/a&gt;: Microsoft 365 Apps and GNU Inetutils&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-52691"target="_blank" rel="noopener"&gt;CVE-2025-52691&lt;/a&gt; and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23760"target="_blank" rel="noopener"&gt;CVE-2026-23760&lt;/a&gt;: SmarterTools SmarterMail&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20045"target="_blank" rel="noopener"&gt;CVE-2026-20045&lt;/a&gt;: Cisco Unified Communications Manager&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-34026"target="_blank" rel="noopener"&gt;CVE-2025-34026&lt;/a&gt;: Versa Concerto&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;No new entries were added to the ENISA KEV catalog in January.&lt;/p&gt;
&lt;p&gt;The Ghost CVE Report reveals early detection of vulnerabilities with limited public information. &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58151"target="_blank" rel="noopener"&gt;CVE-2025-58151&lt;/a&gt; (Xen Security Advisory) and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23456"target="_blank" rel="noopener"&gt;CVE-2026-23456&lt;/a&gt; (YoSmart YoLink Smart Hub) led with 5 sightings each, followed by &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-31884"target="_blank" rel="noopener"&gt;CVE-2024-31884&lt;/a&gt; (4 sightings) and several GHSA identifiers and CVEs with 3 sightings.&lt;/p&gt;
&lt;p&gt;Contributor insights covered a diverse range of topics, including EPMM detection techniques, PAN-OS firewall vulnerabilities, CVEs affecting the Svelte ecosystem, security advisories for Ivanti Endpoint Manager Mobile, GNU C Library updates, Trend Micro Apex Central vulnerabilities, and multiple vulnerabilities in GnuPG (gpg.fail).&lt;/p&gt;
&lt;h2&gt;Top 10 Vendors of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/top-10-vendors.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/top-10-vendors.png" alt="Top 10 Vendors of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 Assigners of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-assigners-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-assigners-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/top-10-assigners.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/top-10-assigners.png" alt="Top 10 Assigners of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21858"target="_blank" rel="noopener"&gt;CVE-2026-21858&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;110&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=n8n-io"target="_blank" rel="noopener"&gt;n8n-io&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=n8n-io&amp;amp;product=n8n"target="_blank" rel="noopener"&gt;n8n&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8071)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24061"target="_blank" rel="noopener"&gt;CVE-2026-24061&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;110&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GNU"target="_blank" rel="noopener"&gt;GNU&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GNU&amp;amp;product=Inetutils"target="_blank" rel="noopener"&gt;Inetutils&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9534)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;97&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta"target="_blank" rel="noopener"&gt;Meta&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta&amp;amp;product=react-server-dom-webpack"target="_blank" rel="noopener"&gt;react-server-dom-webpack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9914)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21509"target="_blank" rel="noopener"&gt;CVE-2026-21509&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;94&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;365&amp;#43;Apps&amp;#43;for&amp;#43;Enterprise"target="_blank" rel="noopener"&gt;Microsoft 365 Apps for Enterprise&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9735)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8088"target="_blank" rel="noopener"&gt;CVE-2025-8088&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=win.rar&amp;#43;GmbH"target="_blank" rel="noopener"&gt;win.rar GmbH&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=win.rar&amp;#43;GmbH&amp;amp;product=WinRAR"target="_blank" rel="noopener"&gt;WinRAR&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9881)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20045"target="_blank" rel="noopener"&gt;CVE-2026-20045&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;80&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Unified&amp;#43;Communications&amp;#43;Manager"target="_blank" rel="noopener"&gt;Cisco Unified Communications Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.5226)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24858"target="_blank" rel="noopener"&gt;CVE-2026-24858&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;80&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiManager"target="_blank" rel="noopener"&gt;FortiManager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9378)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14847"target="_blank" rel="noopener"&gt;CVE-2025-14847&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;76&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MongoDB&amp;#43;Inc."target="_blank" rel="noopener"&gt;MongoDB Inc.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MongoDB&amp;#43;Inc.&amp;amp;product=MongoDB&amp;#43;Server"target="_blank" rel="noopener"&gt;MongoDB Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9349)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1281"target="_blank" rel="noopener"&gt;CVE-2026-1281&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint&amp;#43;Manager&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9914)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=billion"target="_blank" rel="noopener"&gt;billion&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=billion&amp;amp;product=5200w-t"target="_blank" rel="noopener"&gt;5200w-t&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9748)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24858"target="_blank" rel="noopener"&gt;CVE-2026-24858&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-27&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiManager"target="_blank" rel="noopener"&gt;FortiManager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9378)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-52691"target="_blank" rel="noopener"&gt;CVE-2025-52691&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SmarterTools"target="_blank" rel="noopener"&gt;SmarterTools&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SmarterTools&amp;amp;product=SmarterMail"target="_blank" rel="noopener"&gt;SmarterMail&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.7545)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-14634"target="_blank" rel="noopener"&gt;CVE-2018-14634&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=The&amp;#43;Linux&amp;#43;Foundation"target="_blank" rel="noopener"&gt;The Linux Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=The&amp;#43;Linux&amp;#43;Foundation&amp;amp;product=kernel"target="_blank" rel="noopener"&gt;kernel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8719)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23760"target="_blank" rel="noopener"&gt;CVE-2026-23760&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SmarterTools"target="_blank" rel="noopener"&gt;SmarterTools&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SmarterTools&amp;amp;product=SmarterMail"target="_blank" rel="noopener"&gt;SmarterMail&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9916)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-21509"target="_blank" rel="noopener"&gt;CVE-2026-21509&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;365&amp;#43;Apps&amp;#43;for&amp;#43;Enterprise"target="_blank" rel="noopener"&gt;Microsoft 365 Apps for Enterprise&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9735)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-24061"target="_blank" rel="noopener"&gt;CVE-2026-24061&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-26&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GNU"target="_blank" rel="noopener"&gt;GNU&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=GNU&amp;amp;product=Inetutils"target="_blank" rel="noopener"&gt;Inetutils&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9534)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-37079"target="_blank" rel="noopener"&gt;CVE-2024-37079&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-23&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=vcenter_server"target="_blank" rel="noopener"&gt;vcenter_server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9302)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54313"target="_blank" rel="noopener"&gt;CVE-2025-54313&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-22&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=prettier"target="_blank" rel="noopener"&gt;prettier&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=prettier&amp;amp;product=eslint-config-prettier"target="_blank" rel="noopener"&gt;eslint-config-prettier&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8864)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-34026"target="_blank" rel="noopener"&gt;CVE-2025-34026&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-22&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Versa"target="_blank" rel="noopener"&gt;Versa&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Versa&amp;amp;product=Concerto"target="_blank" rel="noopener"&gt;Concerto&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9819)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31125"target="_blank" rel="noopener"&gt;CVE-2025-31125&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-22&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vitejs"target="_blank" rel="noopener"&gt;vitejs&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vitejs&amp;amp;product=vite"target="_blank" rel="noopener"&gt;vite&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.6523)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20045"target="_blank" rel="noopener"&gt;CVE-2026-20045&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-21&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Unified&amp;#43;Communications&amp;#43;Manager"target="_blank" rel="noopener"&gt;Cisco Unified Communications Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.5226)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-20805"target="_blank" rel="noopener"&gt;CVE-2026-20805&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-13&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1607"target="_blank" rel="noopener"&gt;Windows 10 Version 1607&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.995)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8110"target="_blank" rel="noopener"&gt;CVE-2025-8110&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-12&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Gogs"target="_blank" rel="noopener"&gt;Gogs&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Gogs&amp;amp;product=Gogs"target="_blank" rel="noopener"&gt;Gogs&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9905)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2009-0556"target="_blank" rel="noopener"&gt;CVE-2009-0556&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-07&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Office"target="_blank" rel="noopener"&gt;Office&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8535)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-37164"target="_blank" rel="noopener"&gt;CVE-2025-37164&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2026-01-07&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Hewlett&amp;#43;Packard&amp;#43;Enterprise&amp;#43;%28HPE%29"target="_blank" rel="noopener"&gt;Hewlett Packard Enterprise (HPE)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Hewlett&amp;#43;Packard&amp;#43;Enterprise&amp;#43;%28HPE%29&amp;amp;product=HPE&amp;#43;OneView"target="_blank" rel="noopener"&gt;HPE OneView&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.6929)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;ENISA&lt;span class="hx:absolute hx:-mt-20" id="enisa"&gt;&lt;/span&gt;
&lt;a href="#enisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;No new entry in January.&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2026&amp;amp;month=01"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/top-10-weaknesses.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Click the image for more information.&lt;/p&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;Sightings detected between 2026-01-01 and 2026-01-31 that are associated with vulnerabilities without public records.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th style="text-align: right"&gt;Occurrences&lt;/th&gt;
&lt;th&gt;Comment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58151"target="_blank" rel="noopener"&gt;CVE-2025-58151&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;5&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58151#sightings"target="_blank" rel="noopener"&gt;Xen Security Advisory 478 v2&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23456"target="_blank" rel="noopener"&gt;CVE-2026-23456&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;5&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23456#sightings"target="_blank" rel="noopener"&gt;Critical Vulnerabilities in YoSmart YoLink Smart Hub Expose Smart Homes to Remote Attacks&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-31884"target="_blank" rel="noopener"&gt;CVE-2024-31884&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;4&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-31884#sightings"target="_blank" rel="noopener"&gt;Incorrect usage of certificate checking via Pybind&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-7hf5-mc28-xmcv"target="_blank" rel="noopener"&gt;GHSA-7hf5-mc28-xmcv&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-7hf5-mc28-xmcv#sightings"target="_blank" rel="noopener"&gt;CVE-2026-22794: Trust Issues: Hijacking Appsmith Accounts via Origin Header Abuse&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-7g7f-ff96-5gcw"target="_blank" rel="noopener"&gt;GHSA-7g7f-ff96-5gcw&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8217"target="_blank" rel="noopener"&gt;CVE-2025-8217: Amazon Q&amp;rsquo;s Self-Sabotage: The Backdoor That Couldn&amp;rsquo;t Code&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23594"target="_blank" rel="noopener"&gt;CVE-2026-23594&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-23594#sightings"target="_blank" rel="noopener"&gt;Remote Privilege Elevation in HPE Alletra &amp;amp; Nimble Storage&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1220"target="_blank" rel="noopener"&gt;CVE-2026-1220&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-1220#sightings"target="_blank" rel="noopener"&gt;Google Chrome 144 Update Patches High-Severity V8 Vulnerability&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;XXE in OpenCMS&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-12345"target="_blank" rel="noopener"&gt;CVE-2026-12345&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2026-12345#sightings"target="_blank" rel="noopener"&gt;Zero-day RCE in NexusFlow API Gateway is actively exploited&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53086"target="_blank" rel="noopener"&gt;CVE-2025-53086&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53086#sightings"target="_blank" rel="noopener"&gt;The recent patch for HarfBuzz (CVE-2025-53086) addresses a classic yet dangerous heap corruption bug&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-134655"target="_blank" rel="noopener"&gt;CVE-2025-134655&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-134655#sightings"target="_blank" rel="noopener"&gt;prototype pollution flaw&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-63261"target="_blank" rel="noopener"&gt;CVE-2025-63261&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-63261#sightings"target="_blank" rel="noopener"&gt;vulnerability in AWStats as shipped with cPanel&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/2e861f18-01e0-44ba-a7a4-2249e2e5efcf"target="_blank" rel="noopener"&gt;EPMM Nmap detection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/76b43bdc-eede-4898-9809-5183c53c0d0f"target="_blank" rel="noopener"&gt;Detection of EPMM devices&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/973f97c1-de69-4a51-9a06-2ef0ef1baf22"target="_blank" rel="noopener"&gt;PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/d766d344-c029-419a-b990-fb512e9cb929"target="_blank" rel="noopener"&gt;The Ni8mare Test: n8n RCE Under the Microscope (CVE-2026-21858)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/2b58b75c-ed2f-43e6-9955-22f649ee1814"target="_blank" rel="noopener"&gt;CVEs affecting the Svelte ecosystem&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/b6451050-d58c-4bfb-8ea2-a433b2c89297"target="_blank" rel="noopener"&gt;Security Advisory Ivanti Endpoint Manager Mobile (EPMM)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/78ee0d13-7969-4870-8b23-a096918b6dc4"target="_blank" rel="noopener"&gt;The GNU C Library version 2.43 is now available&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/c583fc84-536c-4c66-b98d-5525512bbece"target="_blank" rel="noopener"&gt;CRITICAL SECURITY BULLETIN: Trend Micro Apex Central (on-premise) January 2026 Multiple Vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/2f22146f-462c-4841-9bff-17d8f791e1c2"target="_blank" rel="noopener"&gt;gpg.fail - multiple vulnerabilities in GnuPG&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 4.0.0 released</title><link>http://www.vulnerability-lookup.org/2026/02/16/vulnerability-lookup-4-0-0/</link><pubDate>Mon, 16 Feb 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/02/16/vulnerability-lookup-4-0-0/</guid><description>
&lt;p&gt;We are pleased to announce the release of &lt;strong&gt;Vulnerability-Lookup 4.0.0&lt;/strong&gt; — a second major milestone at the beginning of this year.&lt;/p&gt;
&lt;p&gt;This version is paving the way for federated deployments of Vulnerability-Lookup instances.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Remote Instance Synchronization&lt;span class="hx:absolute hx:-mt-20" id="remote-instance-synchronization"&gt;&lt;/span&gt;
&lt;a href="#remote-instance-synchronization" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;video class="video-shortcode" preload="auto" controls&gt;
&lt;source src="http://www.vulnerability-lookup.org/images/news/2026/02/Vulnerability-Lookup-4.0.0.webm" type="video/webm"&gt;
There should have been a video here but your browser does not seem
to support it.
&lt;/video&gt;
&lt;p&gt;A local instance can now pull objects — including &lt;strong&gt;bundles, comments, sightings, and KEV entries (&lt;a href="https://gcve.eu/2026/02/15/what-s-new-2026-02-15/"target="_blank" rel="noopener"&gt;BCP-07&lt;/a&gt;)&lt;/strong&gt; — from configured remote Vulnerability-Lookup instances via their public APIs.&lt;/p&gt;
&lt;p&gt;The synchronization engine includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Remote instance management with per-object-type synchronization controls&lt;/li&gt;
&lt;li&gt;Timestamp-based update detection to keep data consistent&lt;/li&gt;
&lt;li&gt;Asynchronous scheduler with graceful shutdown support&lt;/li&gt;
&lt;li&gt;CLI command and systemd service template for automation&lt;/li&gt;
&lt;li&gt;Administrative controls to trigger synchronization manually&lt;/li&gt;
&lt;li&gt;Visual indicators in the interface to clearly identify synchronized objects&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This enables controlled federation between trusted instances while maintaining operational visibility.&lt;/p&gt;
&lt;p&gt;The documentation is available &lt;a href="https://www.vulnerability-lookup.org/documentation/sync.html"target="_blank" rel="noopener"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Remote instances configuration&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/remote_instances.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/remote_instances.png" alt="Remote instances configuration" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;About page listing configured remote instances&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/about_page.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/about_page.png" alt="About page listing configured remote instances" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Synced comments&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/sync_comments.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/sync_comments.png" alt="Synced comments" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Synced KEV Catalogs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/sync_catalogs.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/sync_catalogs.png" alt="Synced KEV Catalogs - 1" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/sync_kev.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/sync_kev.png" alt="Synced KEV Catalogs - 2" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;New Security Advisory Sources&lt;span class="hx:absolute hx:-mt-20" id="new-security-advisory-sources"&gt;&lt;/span&gt;
&lt;a href="#new-security-advisory-sources" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Two new feeders expand Vulnerability-Lookup’s ingestion capabilities:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;RustSec OSV feeder&lt;/strong&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/bf0c435"target="_blank" rel="noopener"&gt;bf0c435&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;OSS-Fuzz feeder&lt;/strong&gt; with support for YAML sources in OSV
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/21f2309"target="_blank" rel="noopener"&gt;21f2309&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/sources.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/sources.png" alt="New sources" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Improved global dashboard layout for better clarity and navigation
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/91db7fd"target="_blank" rel="noopener"&gt;91db7fd&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;CSAF and OSV templates made fully generic
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/418b590"target="_blank" rel="noopener"&gt;418b590&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Timestamps are now consistently converted to UTC before JSON serialization, preventing timezone mislabeling when the database session runs in a non-UTC timezone
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/4f7149e"target="_blank" rel="noopener"&gt;4f7149e&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;API updated to handle the new data format returned by Rulezet
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5489d29"target="_blank" rel="noopener"&gt;5489d29&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;For the complete list of changes, please refer to the GitHub release notes:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v4.0.0"target="_blank" rel="noopener"&gt;v4.0.0 Release Notes&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, please open a ticket on our GitHub repository:
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues"target="_blank" rel="noopener"&gt;GitHub Issues&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow Us on the Fediverse&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-the-fediverse"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-the-fediverse" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories and project news in real time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;@vulnerability_lookup&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 3.0.0 released</title><link>http://www.vulnerability-lookup.org/2026/02/02/vulnerability-lookup-3-0-0/</link><pubDate>Mon, 02 Feb 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/02/02/vulnerability-lookup-3-0-0/</guid><description>
&lt;p&gt;We are glad to announce Vulnerability-Lookup 3.0.0. Our second release of 2026 is a major milestone, featuring &lt;a href="https://gcve.eu/bcp/gcve-bcp-07/"target="_blank" rel="noopener"&gt;GCVE-BCP-07&lt;/a&gt; support.
Now, every Vulnerability-Lookup instance can publish its own KEV catalog while integrating KEV feeds from &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"target="_blank" rel="noopener"&gt;CISA&lt;/a&gt; and &lt;a href="https://euvd.enisa.europa.eu"target="_blank" rel="noopener"&gt;ENISA&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let’s take a look at all the notable changes.&lt;/p&gt;
&lt;h3&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;GCVE-BCP-07: Known Exploited Vulnerabilities (KEV) Catalogs Integration&lt;span class="hx:absolute hx:-mt-20" id="gcve-bcp-07-known-exploited-vulnerabilities-kev-catalogs-integration"&gt;&lt;/span&gt;
&lt;a href="#gcve-bcp-07-known-exploited-vulnerabilities-kev-catalogs-integration" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;video class="video-shortcode" preload="auto" controls&gt;
&lt;source src="http://www.vulnerability-lookup.org/images/news/2026/02/Vulnerability-Lookup-3.0.0.webm" type="video/webm"&gt;
There should have been a video here but your browser does not seem
to support it.
&lt;/video&gt;
&lt;p&gt;This release implements support for GCVE-BCP-07, enabling seamless integration with multiple Known Exploited Vulnerabilities (KEV) catalogs from different Global Numbering Authorities (GNAs).
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/310"target="_blank" rel="noopener"&gt;PR #310&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Out of the box, any Vulnerability-Lookup instance can publish its own GCVE-BCP-07–compliant KEV catalog and consume KEV catalogs from ENISA and CISA.
Conversion and synchronization are performed using the following tool:
&lt;a href="https://github.com/gcve-eu/gcve-eu-kev"target="_blank" rel="noopener"&gt;https://github.com/gcve-eu/gcve-eu-kev&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A huge thank you to CISA and ENISA for their continuous work and for making KEV data available. Their catalogs are key building blocks for effective vulnerability prioritization, and it’s great to see them fit naturally into a GCVE-aligned workflow.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-CIRCL.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-CIRCL.png" alt="KEV CIRCL" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-CISA.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-CISA.png" alt="KEV CISA" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-EUVD.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-EUVD.png" alt="KEV EUVD" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-detail-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-detail-1.png" alt="KEV entry detail - 1" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-detail-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-detail-2.png" alt="KEV entry detail - 2" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-vuln-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-vuln-1.png" alt="KEV vulnerability view" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-Add-entry.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/KEV-Add-entry.png" alt="KEV new entry" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;New and updated tools&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;CISA KEV and ENISA CNW EUVD to &lt;strong&gt;GCVE-BCP-07 Converter&lt;/strong&gt;: &lt;a href="https://github.com/gcve-eu/gcve-eu-kev"target="_blank" rel="noopener"&gt;https://github.com/gcve-eu/gcve-eu-kev&lt;/a&gt;&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ gcve-from-cisa --push
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ gcve-from-enisa --push&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;BCP Validator&lt;/strong&gt;: &lt;a href="https://github.com/gcve-eu/bcp-validator"target="_blank" rel="noopener"&gt;https://github.com/gcve-eu/bcp-validator&lt;/a&gt;&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ python gcve_bcp05_validate.py --url https://vulnerability.circl.lu/api/vulnerability?source&lt;span class="o"&gt;=&lt;/span&gt;gna-1
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;OK: https://vulnerability.circl.lu/api/vulnerability/recent?source&lt;span class="o"&gt;=&lt;/span&gt;gna-1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;GCVE &lt;strong&gt;Python client&lt;/strong&gt;: &lt;a href="https://github.com/gcve-eu/gcve"target="_blank" rel="noopener"&gt;https://github.com/gcve-eu/gcve&lt;/a&gt;&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ gcve references --list
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;kev&amp;#34;&lt;/span&gt;: &lt;span class="o"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;405284c2-e461-4670-8979-7fd2c9755a60&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;short_name&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;CISA KEV&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;automation_url&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;For the benefit of the cybersecurity community and network defenders\u2014and to help every organization better manage vulnerabilities and keep pace with threat activity\u2014CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;1a89b78e-f703-45f3-bb86-59eb712668bd&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;short_name&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;CIRCL&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;gcve_gna_id&amp;#34;&lt;/span&gt;: 1,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;CIRCL provides a known-exploited vulnerability and supporting the different status_reason described in GCVE BCP-07.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;cce329bf-df49-4c6e-a027-80be2e6483bd&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;short_name&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;EUVD KEV&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;gcve_gna_id&amp;#34;&lt;/span&gt;: 2,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;automation_url&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;https://github.com/enisaeu/CNW/raw/refs/heads/main/kev.csv&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;ENISA via the CSIRTs network provides list of known-exploited seen in the CSIRTs network.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;New Vulnerability Sources&lt;span class="hx:absolute hx:-mt-20" id="new-vulnerability-sources"&gt;&lt;/span&gt;
&lt;a href="#new-vulnerability-sources" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/02/New-feeds.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/02/New-feeds.png" alt="New feeds" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;new: [feeders] OSV importer for &lt;strong&gt;Drupal&lt;/strong&gt; security advisories. Imports vulnerabilities from the Drupal security team&amp;rsquo;s OSV feed.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/14177ab"target="_blank" rel="noopener"&gt;14177ab&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;new: [feeders] OSV importer for &lt;strong&gt;CleanStart&lt;/strong&gt; security advisories. Imports vulnerabilities from CleanStart&amp;rsquo;s OSV feed.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/14177ab"target="_blank" rel="noopener"&gt;14177ab&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;new: [feeders] &lt;strong&gt;Bitnami&lt;/strong&gt; Vulnerability Database importer. Imports vulnerabilities from Bitnami&amp;rsquo;s OSV-formatted vulnerability database, covering their application catalog.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/165e99d"target="_blank" rel="noopener"&gt;165e99d&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;chg: [gcve] Updated GCVE Python client with improved type hints and bug fixes.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/78dbfc1"target="_blank" rel="noopener"&gt;78dbfc1&lt;/a&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5ddf74d"target="_blank" rel="noopener"&gt;5ddf74d&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;chg: [gcve] KEV catalog menu now handles production instances that have their own GNA ID. When a local instance (e.g., CIRCL - GNA-1) exists in the GCVE KEV catalog list, it&amp;rsquo;s marked as local without creating duplicates.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2bba2d8"target="_blank" rel="noopener"&gt;2bba2d8&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;chg: [api] Extended x_gcve injection to all vulnerability list endpoints: VulnerabilitiesList, Recent, Last, and LastLegacy. This ensures consistent GCVE integration across all API endpoints.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/227da00"target="_blank" rel="noopener"&gt;227da00&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Various graphical improvements.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;fix: [gcve] Resolved circular import in gcve_utils module.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e7aa364"target="_blank" rel="noopener"&gt;e7aa364&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&amp;lsquo;Ghost CVEs&amp;rsquo; toggle is wonky
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/303"target="_blank" rel="noopener"&gt;#303&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Fix CVSS 4.0 parsing crash in web filters
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/304"target="_blank" rel="noopener"&gt;#304&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Fix blacklist bypass vulnerability in username validation
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/314/commits"target="_blank" rel="noopener"&gt;#314&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Support YYYYMMDD date format in API since parameter
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/315"target="_blank" rel="noopener"&gt;#315&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v3.0.0"target="_blank" rel="noopener"&gt;v3.0.0 Release Notes&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Thank you to all our contributors and testers!&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;GitHub Issues&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow Us on the Fediverse&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-the-fediverse"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-the-fediverse" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;@vulnerability_lookup&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.21.0 released</title><link>http://www.vulnerability-lookup.org/2026/01/23/vulnerability-lookup-2-21-0/</link><pubDate>Fri, 23 Jan 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/01/23/vulnerability-lookup-2-21-0/</guid><description>
&lt;p&gt;We’re delighted to announce the release of Vulnerability-Lookup 2.21.0.
This release brings several important improvements focused on search, data ingestion, and usability.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Product-level indexing &amp;amp; search API&lt;span class="hx:absolute hx:-mt-20" id="product-level-indexing--search-api"&gt;&lt;/span&gt;
&lt;a href="#product-level-indexing--search-api" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Making it easier to explore vulnerabilities from a product-centric angle, without specifying a vendor name.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f906064"target="_blank" rel="noopener"&gt;f906064&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/product-search-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/product-search-1.png" alt="Product search - example 1" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/product-search-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/product-search-2.png" alt="Product search - example 2" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;New CSAF feeder for Schneider Electric&lt;span class="hx:absolute hx:-mt-20" id="new-csaf-feeder-for-schneider-electric"&gt;&lt;/span&gt;
&lt;a href="#new-csaf-feeder-for-schneider-electric" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;We have recently added a new &lt;a href="https://vulnerability.circl.lu/recent#csaf_se"target="_blank" rel="noopener"&gt;CSAF feed for Schneider Electric&lt;/a&gt;.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e43fa03"target="_blank" rel="noopener"&gt;e43fa03&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/csaf-schneider-electric.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/csaf-schneider-electric.png" alt="CSAF feeder for Schneider Electric" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;More flexible user registration configuration&lt;span class="hx:absolute hx:-mt-20" id="more-flexible-user-registration-configuration"&gt;&lt;/span&gt;
&lt;a href="#more-flexible-user-registration-configuration" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;New options to customize signup/about pages and restrict accepted email domains.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3855838"target="_blank" rel="noopener"&gt;3855838&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/bfc82cf"target="_blank" rel="noopener"&gt;bfc82cf&lt;/a&gt;)&lt;/p&gt;
&lt;h3&gt;Improved notifications &amp;amp; UI refinements&lt;span class="hx:absolute hx:-mt-20" id="improved-notifications--ui-refinements"&gt;&lt;/span&gt;
&lt;a href="#improved-notifications--ui-refinements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Clearer emails, better metadata, and cleaner templates.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/email-notification.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/email-notification.png" alt="Email notifcation" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ghost CVE&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We now use the term &lt;em&gt;Ghost CVE&lt;/em&gt; to refer to vulnerabilities observed in the wild via sightings
that do not yet have a public CVE record.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/ghost-cve.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/ghost-cve.png" alt="Ghost CVE" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A number of fixes and technical improvements are also included.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;chg: [notifications] Added the publication date in email notifications and
a special icon for new vulnerabilities. Closes #299.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/64bc631"target="_blank" rel="noopener"&gt;64bc631&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [dependencies] Updated Python and dev/docs dependencies.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/510233c"target="_blank" rel="noopener"&gt;510233c&lt;/a&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/b08c381"target="_blank" rel="noopener"&gt;b08c381&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [config] Updated default value for &lt;code&gt;ACCEPTED_DOMAINS_FOR_REGISTRATION&lt;/code&gt;.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/6563f8a"target="_blank" rel="noopener"&gt;6563f8a&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Simplified titles for vuln and sightings pages; added
Open Graph meta tag.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/19c9a69"target="_blank" rel="noopener"&gt;19c9a69&lt;/a&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/27eb6bf"target="_blank" rel="noopener"&gt;27eb6bf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [documentation] Updated installation instructions.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/152212d"target="_blank" rel="noopener"&gt;152212d&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;fix: [api] Preserve typing for flask-restx decorators (mypy).
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f5f31c5"target="_blank" rel="noopener"&gt;f5f31c5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix(cvss): Safely handle CVSS 4.0 vectors in Jinja filters. Closes #305.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5a303bb"target="_blank" rel="noopener"&gt;5a303bb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [templates] Fix Bootstrap switch click handling (moved popover to
help icon). Closes #303.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/19a8c54"target="_blank" rel="noopener"&gt;19a8c54&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [bin] Corrected the script name for the CSAF Schneider Electric importer.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1386a76"target="_blank" rel="noopener"&gt;1386a76&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [templates] Fixed an issue with batch deletion of users.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/839345b"target="_blank" rel="noopener"&gt;839345b&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [templates] Fixed a tag id in vulnerability_templates.html.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/bc0d329"target="_blank" rel="noopener"&gt;bc0d329&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.21.0"target="_blank" rel="noopener"&gt;v2.21.0 Release Notes&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Thank you to all our contributors and testers!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The new contributor of this release is &lt;a href="https://github.com/thaicn1712"target="_blank" rel="noopener"&gt;Thai Nguyen&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;GitHub Issues&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow Us on the Fediverse&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-the-fediverse"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-the-fediverse" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;@vulnerability_lookup&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - December 2025</title><link>http://www.vulnerability-lookup.org/2026/01/12/vulnerability-report-december-2025/</link><pubDate>Mon, 12 Jan 2026 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2026/01/12/vulnerability-report-december-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for December 2025, based on sightings collected from various sources,
including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, Metasploit, and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A new section dedicated to &lt;a href="#detection-rules"&gt;detection rules&lt;/a&gt; is available.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;December 2025 was dominated by a &lt;strong&gt;massive surge&lt;/strong&gt; in activity surrounding &lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/strong&gt; affecting Meta&amp;rsquo;s &lt;em&gt;react-server-dom-webpack&lt;/em&gt;. With &lt;strong&gt;852 sightings&lt;/strong&gt;, this critical vulnerability (referenced by contributors as &amp;ldquo;React2Shell&amp;rdquo;) significantly outpaced all other vulnerabilities, highlighting a major focus on web application infrastructure exploitation.&lt;/p&gt;
&lt;p&gt;Database and network security were also primary themes this month. &lt;strong&gt;MongoDB&lt;/strong&gt; (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14847"target="_blank" rel="noopener"&gt;CVE-2025-14847&lt;/a&gt;) ranked second in sightings and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on December 29th. The networking sector remained volatile, with critical vulnerabilities in &lt;strong&gt;Cisco Secure Email&lt;/strong&gt;, &lt;strong&gt;WatchGuard Fireware OS&lt;/strong&gt;, &lt;strong&gt;Fortinet&lt;/strong&gt;, and &lt;strong&gt;SonicWall&lt;/strong&gt; appearing in both the top sightings and the CISA KEV list.&lt;/p&gt;
&lt;p&gt;Despite the influx of 2025 vulnerabilities, &amp;ldquo;zombie&amp;rdquo; vulnerabilities continue to plague the internet. Legacy issues from 2015 (D-Link) and 2017 (Zyxel) persist in the Top 10, proving that unpatched IoT devices remain active attack vectors years after disclosure.&lt;/p&gt;
&lt;p&gt;In the broader ecosystem, CISA added a wide variety of threats to their catalog, ranging from mobile operating systems (&lt;strong&gt;iOS&lt;/strong&gt;, &lt;strong&gt;Android&lt;/strong&gt;) and browsers (&lt;strong&gt;Chrome&lt;/strong&gt;) to desktop utilities like &lt;strong&gt;WinRAR&lt;/strong&gt;. Additionally, community contributors highlighted significant structural shifts, notably the End-of-Life status for the &lt;strong&gt;Linux 5.4 kernel&lt;/strong&gt; and new cryptographic implementation flaws in &lt;strong&gt;GnuPG&lt;/strong&gt;.&lt;/p&gt;
&lt;h2&gt;Evolution of published CVE in 2025&lt;span class="hx:absolute hx:-mt-20" id="evolution-of-published-cve-in-2025"&gt;&lt;/span&gt;
&lt;a href="#evolution-of-published-cve-in-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/evolution-cve-2025.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/evolution-cve-2025.png" alt="Evolution of published CVE in 2025" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/stats/"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Top 10 Vendors of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/top-10-vendors.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/top-10-vendors.png" alt="Top 10 Vendors of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 Assigners of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-assigners-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-assigners-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2026/01/top-10-assigners.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/top-10-assigners.png" alt="Top 10 Assigners of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;852&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta"target="_blank" rel="noopener"&gt;Meta&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta&amp;amp;product=react-server-dom-webpack"target="_blank" rel="noopener"&gt;react-server-dom-webpack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9783)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14847"target="_blank" rel="noopener"&gt;CVE-2025-14847&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;204&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MongoDB&amp;#43;Inc."target="_blank" rel="noopener"&gt;MongoDB Inc.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MongoDB&amp;#43;Inc.&amp;amp;product=MongoDB&amp;#43;Server"target="_blank" rel="noopener"&gt;MongoDB Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9538)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20393"target="_blank" rel="noopener"&gt;CVE-2025-20393&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;89&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Secure&amp;#43;Email"target="_blank" rel="noopener"&gt;Cisco Secure Email&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.5137)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.607)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;zyxel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;p660hn-t1a_v1&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9763)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14733"target="_blank" rel="noopener"&gt;CVE-2025-14733&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WatchGuard"target="_blank" rel="noopener"&gt;WatchGuard&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WatchGuard&amp;amp;product=Fireware&amp;#43;OS"target="_blank" rel="noopener"&gt;Fireware OS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.976)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66516"target="_blank" rel="noopener"&gt;CVE-2025-66516&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;57&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache&amp;#43;Software&amp;#43;Foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache&amp;#43;Software&amp;#43;Foundation&amp;amp;product=Apache&amp;#43;Tika&amp;#43;core"target="_blank" rel="noopener"&gt;Apache Tika core&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8155)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;56&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks"target="_blank" rel="noopener"&gt;dasannetworks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks&amp;amp;product=gpon_router"target="_blank" rel="noopener"&gt;gpon_router&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9815)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-40602"target="_blank" rel="noopener"&gt;CVE-2025-40602&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;53&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SonicWall"target="_blank" rel="noopener"&gt;SonicWall&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SonicWall&amp;amp;product=SMA1000"target="_blank" rel="noopener"&gt;SMA1000&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9162)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59718"target="_blank" rel="noopener"&gt;CVE-2025-59718&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;53&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiSwitchManager"target="_blank" rel="noopener"&gt;FortiSwitchManager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.7339)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14847"target="_blank" rel="noopener"&gt;CVE-2025-14847&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MongoDB&amp;#43;Inc."target="_blank" rel="noopener"&gt;MongoDB Inc.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MongoDB&amp;#43;Inc."target="_blank" rel="noopener"&gt;MongoDB Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9538)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-52163"target="_blank" rel="noopener"&gt;CVE-2023-52163&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;22/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=digiever"target="_blank" rel="noopener"&gt;digiever&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=digiever&amp;amp;product=ds-2105_pro"target="_blank" rel="noopener"&gt;ds-2105_pro&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9141)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14733"target="_blank" rel="noopener"&gt;CVE-2025-14733&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WatchGuard"target="_blank" rel="noopener"&gt;WatchGuard&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WatchGuard&amp;amp;product=Fireware&amp;#43;OS"target="_blank" rel="noopener"&gt;Fireware OS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.976)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20393"target="_blank" rel="noopener"&gt;CVE-2025-20393&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Secure&amp;#43;Email"target="_blank" rel="noopener"&gt;Cisco Secure Email&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.5137)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-40602"target="_blank" rel="noopener"&gt;CVE-2025-40602&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SonicWall"target="_blank" rel="noopener"&gt;SonicWall&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SonicWall&amp;amp;product=SMA1000"target="_blank" rel="noopener"&gt;SMA1000&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9162)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59374"target="_blank" rel="noopener"&gt;CVE-2025-59374&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ASUS"target="_blank" rel="noopener"&gt;ASUS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ASUS&amp;amp;product=live&amp;#43;update"target="_blank" rel="noopener"&gt;live update&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.7584)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59718"target="_blank" rel="noopener"&gt;CVE-2025-59718&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;16/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiSwitchManager"target="_blank" rel="noopener"&gt;FortiSwitchManager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.7339)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43529"target="_blank" rel="noopener"&gt;CVE-2025-43529&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=iOS&amp;#43;and&amp;#43;iPadOS"target="_blank" rel="noopener"&gt;iOS and iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9918)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14611"target="_blank" rel="noopener"&gt;CVE-2025-14611&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Gladinet"target="_blank" rel="noopener"&gt;Gladinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Gladinet&amp;amp;product=CentreStack&amp;#43;and&amp;#43;TrioFox"target="_blank" rel="noopener"&gt;CentreStack and TrioFox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8669)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14174"target="_blank" rel="noopener"&gt;CVE-2025-14174&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8175)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-4063"target="_blank" rel="noopener"&gt;CVE-2018-4063&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sierrawireless"target="_blank" rel="noopener"&gt;sierrawireless&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sierrawireless&amp;amp;product=aleos"target="_blank" rel="noopener"&gt;aleos&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7137)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58360"target="_blank" rel="noopener"&gt;CVE-2025-58360&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;11/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=geoserver"target="_blank" rel="noopener"&gt;geoserver&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=geoserver&amp;amp;product=geoserver"target="_blank" rel="noopener"&gt;geoserver&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5288)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-62221"target="_blank" rel="noopener"&gt;CVE-2025-62221&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9943)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6218"target="_blank" rel="noopener"&gt;CVE-2025-6218&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=RARLAB"target="_blank" rel="noopener"&gt;RARLAB&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=RARLAB&amp;amp;product=WinRAR"target="_blank" rel="noopener"&gt;WinRAR&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9977)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66644"target="_blank" rel="noopener"&gt;CVE-2025-66644&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;08/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Array&amp;#43;Networks"target="_blank" rel="noopener"&gt;Array Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Array&amp;#43;Networks&amp;amp;product=ArrayOS&amp;#43;AG"target="_blank" rel="noopener"&gt;ArrayOS AG&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8361)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-37055"target="_blank" rel="noopener"&gt;CVE-2022-37055&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;08/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=go-rt-ac750"target="_blank" rel="noopener"&gt;go-rt-ac750&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9698)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;05/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta"target="_blank" rel="noopener"&gt;Meta&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Meta&amp;amp;product=react-server-dom-webpack"target="_blank" rel="noopener"&gt;react-server-dom-webpack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9783)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-26828"target="_blank" rel="noopener"&gt;CVE-2021-26828&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;03/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=scadabr"target="_blank" rel="noopener"&gt;scadabr&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=scadabr&amp;amp;product=scadabr"target="_blank" rel="noopener"&gt;scadabr&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.7378)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48633"target="_blank" rel="noopener"&gt;CVE-2025-48633&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Android"target="_blank" rel="noopener"&gt;Android&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8796)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48572"target="_blank" rel="noopener"&gt;CVE-2025-48572&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/12/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Android"target="_blank" rel="noopener"&gt;Android&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9629)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;ENISA&lt;span class="hx:absolute hx:-mt-20" id="enisa"&gt;&lt;/span&gt;
&lt;a href="#enisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;No new entry in December.&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2025&amp;amp;month=12"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2026/01/top-10-weaknesses.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Click the image for more information.&lt;/p&gt;
&lt;h2&gt;Detection rules&lt;span class="hx:absolute hx:-mt-20" id="detection-rules"&gt;&lt;/span&gt;
&lt;a href="#detection-rules" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55182"target="_blank" rel="noopener"&gt;CVE-2025-55182&lt;/a&gt;&lt;span class="hx:absolute hx:-mt-20" id="cve-2025-55182"&gt;&lt;/span&gt;
&lt;a href="#cve-2025-55182" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://rulezet.org/rule/detail_rule/182885"target="_blank" rel="noopener"&gt;ET WEB_SPECIFIC_APPS Waku RSC React2Shell Unsafe Flight Protocol Property Access&lt;/a&gt; [SURICATA]&lt;/li&gt;
&lt;li&gt;&lt;a href="https://rulezet.org/rule/detail_rule/182884"target="_blank" rel="noopener"&gt;ET WEB_SPECIFIC_APPS Vite RSC React2Shell Unsafe Flight Protocol Property Access&lt;/a&gt; [SURICATA]&lt;/li&gt;
&lt;li&gt;&lt;a href="https://rulezet.org/rule/detail_rule/182883"target="_blank" rel="noopener"&gt;ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access&lt;/a&gt; [SURICATA]&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;span class="hx:absolute hx:-mt-20" id="cve-2015-2051"&gt;&lt;/span&gt;
&lt;a href="#cve-2015-2051" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://rulezet.org/rule/detail_rule/182790"target="_blank" rel="noopener"&gt;ET EXPLOIT D-Link HNAP SOAPAction Command Injection&lt;/a&gt; [SURICATA]&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;span class="hx:absolute hx:-mt-20" id="cve-2017-18368"&gt;&lt;/span&gt;
&lt;a href="#cve-2017-18368" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://rulezet.org/rule/detail_rule/157391"target="_blank" rel="noopener"&gt;ET EXPLOIT Possible ZyXEL P660HN-T v1 RCE&lt;/a&gt; [SURICATA]&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66516"target="_blank" rel="noopener"&gt;CVE-2025-66516&lt;/a&gt;&lt;span class="hx:absolute hx:-mt-20" id="cve-2025-66516"&gt;&lt;/span&gt;
&lt;a href="#cve-2025-66516" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://rulezet.org/rule/detail_rule/183065"target="_blank" rel="noopener"&gt;ET WEB_SPECIFIC_APPS Apache Tika XML External Entity Injection&lt;/a&gt; [SURICATA]&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-52163"target="_blank" rel="noopener"&gt;CVE-2023-52163&lt;/a&gt;&lt;span class="hx:absolute hx:-mt-20" id="cve-2023-52163"&gt;&lt;/span&gt;
&lt;a href="#cve-2023-52163" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://rulezet.org/rule/detail_rule/178589"target="_blank" rel="noopener"&gt;ET WEB_SPECIFIC_APPS DigiEver DS-2105 Pro time_tzsetup.cgi ntp Parameter Command Injection Attempt&lt;/a&gt; [SURICATA]&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;Sightings detected between 2025-12-01 and 2025-12-31 that are associated with vulnerabilities without public records.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th style="text-align: right"&gt;Occurrences&lt;/th&gt;
&lt;th&gt;Comment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;11&lt;/td&gt;
&lt;td&gt;&lt;a href="https://blog.qualys.com/product-tech/2023/12/08/opencms-unauthenticated-xxe-vulnerability-cve-2023-42344"target="_blank" rel="noopener"&gt;OpenCMS Unauthenticated XXE Vulnerability&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14269"target="_blank" rel="noopener"&gt;CVE-2025-14269&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;9&lt;/td&gt;
&lt;td&gt;&lt;a href="https://seclists.org/oss-sec/2025/q4/284"target="_blank" rel="noopener"&gt;Credential caching in Headlamp with Helm enabled&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14282"target="_blank" rel="noopener"&gt;CVE-2025-14282&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;6&lt;/td&gt;
&lt;td&gt;&lt;a href="https://seclists.org/oss-sec/2025/q4/282"target="_blank" rel="noopener"&gt;dropbear: privilege escalation via unix domain socket forwardings&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14558"target="_blank" rel="noopener"&gt;CVE-2025-14558&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;5&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc"target="_blank" rel="noopener"&gt;FreeBSD IPv6 Flaw Enables Remote Code Execution Attacks&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9820"target="_blank" rel="noopener"&gt;CVE-2025-9820&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://seclists.org/oss-sec/2025/q4/203"target="_blank" rel="noopener"&gt;gnutls 3.8.11 released with fix for CVE-2025-9820&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66387"target="_blank" rel="noopener"&gt;CVE-2025-66387&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://levelblue.com/blogs/spiderlabs-blog/levelblue-spiderlabs-sql-injection-in-orkes-conductor-cve-2025-66387/"target="_blank" rel="noopener"&gt;QL Injection in Orkes Conductor&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-65995"target="_blank" rel="noopener"&gt;CVE-2025-65995&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://seclists.org/oss-sec/2025/q4/271"target="_blank" rel="noopener"&gt;Apache Airflow: Disclosure of secrets to UI via kwargs&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/2f22146f-462c-4841-9bff-17d8f791e1c2"target="_blank" rel="noopener"&gt;gpg.fail - multiple vulnerabilities in GnuPG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/6739b288-995a-4f1a-9f03-5d1ced3a8fbd"target="_blank" rel="noopener"&gt;React2Shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/816dcc8e-f25a-4895-9b59-1bbd9caeccb8"target="_blank" rel="noopener"&gt;The LAST Linux 5.4.y release. It is now end-of-life and should not be &amp;gt; used by anyone, anymore.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/63aa0cf1-252d-490e-8492-fbddac588c54"target="_blank" rel="noopener"&gt;Apache Tika&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/c5b7cfe4-31dc-48ad-9aad-8e8bd3c6bf83"target="_blank" rel="noopener"&gt;Security content of iOS 26.2 and iPadOS 26.2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/fa5775cb-515d-41b8-b18e-c17a50ec6630"target="_blank" rel="noopener"&gt;Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manage&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.20.0 released</title><link>http://www.vulnerability-lookup.org/2025/12/19/vulnerability-lookup-2-20-0/</link><pubDate>Fri, 19 Dec 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/12/19/vulnerability-lookup-2-20-0/</guid><description>
&lt;p&gt;Just in time for the end of the year, we’re happy to share our final release before the holidays: &lt;strong&gt;Vulnerability-Lookup 2.20.0&lt;/strong&gt; 🎄&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;GCVE (Global CVE Allocation System): Relationships&lt;span class="hx:absolute hx:-mt-20" id="gcve-global-cve-allocation-system-relationships"&gt;&lt;/span&gt;
&lt;a href="#gcve-global-cve-allocation-system-relationships" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;We’ve updated the bundled Vulnogram interface to better support the GCVE ecosystem. Vulnerability-Lookup now allows you to define and manage relationships between vulnerabilities, in line with the &lt;a href="https://gcve.eu/bcp/gcve-bcp-05/#relationships-field"target="_blank" rel="noopener"&gt;GCVE BCP-05 specification&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2f39bf8659aeda081780db65d0c6f9e769427110"target="_blank" rel="noopener"&gt;Commit: 2f39bf8&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This is a first step toward implementing full GCVE BCP-05 compliance.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Displaying relationships of a vulnerability&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/relationships-view.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/relationships-view.png" alt="Displaying relationships of a vulnerability" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0032"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/GCVE-1-2025-0032&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In this case, &lt;code&gt;opposes&lt;/code&gt; indicates that the GNA does not agree with the status or validity of the referenced vulnerability. This can be used when a GCVE published by another GNA is considered not to be a vulnerability for the product in question (e.g., the behavior is expected, or the scenario describes a discouraged or unsupported configuration).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Editing relationships with the Vulnogram UI&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/relationships-edit.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/relationships-edit.png" alt="Edition relationships with Vulnogram user interface" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h3&gt;Sightings Visualization&lt;span class="hx:absolute hx:-mt-20" id="sightings-visualization"&gt;&lt;/span&gt;
&lt;a href="#sightings-visualization" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Understanding how vulnerabilities are observed in the wild just got easier. We’ve added a new &lt;strong&gt;Heat Map&lt;/strong&gt; to visualize vulnerability sightings over time, featuring built-in filters for dates and sighting types.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/56a66e0ef045e299e8fcd41fa85afa16068e1d56"target="_blank" rel="noopener"&gt;Commit: 56a66e0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Heatmap for sightings&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;video controls src="http://www.vulnerability-lookup.org/images/news/2025/12/heatmap.webm" title="Sightings Heatmap Demo"&gt;&lt;/video&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Examples&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/heat-map-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/heat-map-1.png" alt="Heatmap example 1" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61757#sightings"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/CVE-2025-61757#sightings&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/heat-map-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/heat-map-2.png" alt="Heatmap example 2" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/bar-chart-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/bar-chart-2.png" alt="Bar chart" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-13379#sightings"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/CVE-2018-13379#sightings&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sighting correlations&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-correlations.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-correlations.png" alt="Sighting correlations" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59718#sightingsCorrelations"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/CVE-2025-59718#sightingsCorrelations&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Authentication:&lt;/strong&gt; Allowed password recovery triggers based on case-insensitive usernames. &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/290"target="_blank" rel="noopener"&gt;#290&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability Disclosure:&lt;/strong&gt; A guidance message is now displayed to unauthenticated users when attempting to submit a new disclosure. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/90787db278f7a856f3d3fb18193d39b9c73ed87f"target="_blank" rel="noopener"&gt;90787db&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Product API:&lt;/strong&gt; &lt;code&gt;product.find_vulnerabilities&lt;/code&gt; now returns more comprehensive results. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a31f6c3689f1c53d0e2678f761ae01734a1ad858"target="_blank" rel="noopener"&gt;a31f6c3&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/CVE-tags.png" alt="CVE tags example" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0041"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/GCVE-1-2025-0041&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Data Ingestion:&lt;/strong&gt; Fixed an issue to ignore temporary files in &lt;code&gt;ossf/malicious-packages&lt;/code&gt;. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/6bc93b1608606b274bf25f7ef341f4a57627630b"target="_blank" rel="noopener"&gt;6bc93b1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Website:&lt;/strong&gt; Fixed the routing path used to delete vulnerability disclosures. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e2ecb2a33952b034a5bbbeac3d9eed8568ad3958"target="_blank" rel="noopener"&gt;e2ecb2a&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Website:&lt;/strong&gt; Updated vulnerability ID requirements to be optional for disclosures. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5bd5353462afbd4164e7d825976964c03d1dc49a"target="_blank" rel="noopener"&gt;5bd5353&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.20.0"target="_blank" rel="noopener"&gt;v2.20.0 Release Notes&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Thank you to all our contributors and testers!&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;GitHub Issues&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow Us on the Fediverse&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-the-fediverse"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-the-fediverse" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;@vulnerability_lookup&lt;/a&gt;&lt;/p&gt;</description></item><item><title>GPU Efficiency in VLAI Model Training</title><link>http://www.vulnerability-lookup.org/2025/12/12/gpu-efficiency-in-vlai-model-training/</link><pubDate>Fri, 12 Dec 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/12/12/gpu-efficiency-in-vlai-model-training/</guid><description>
&lt;div class="hx:overflow-x-auto hx:mt-6 hx:flex hx:rounded-lg hx:border hx:py-2 hx:ltr:pr-4 hx:rtl:pl-4 hx:contrast-more:border-current hx:contrast-more:dark:border-current hx:border-blue-200 hx:bg-blue-100 hx:text-blue-900 hx:dark:border-blue-200/30 hx:dark:bg-blue-900/30 hx:dark:text-blue-200"&gt;
&lt;div class="hx:ltr:pl-3 hx:ltr:pr-2 hx:rtl:pr-3 hx:rtl:pl-2"&gt;&lt;svg height=1.2em class="hx:inline-block hx:align-middle" xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M13 16h-1v-4h-1m1-4h.01M21 12a9 9 0 11-18 0 9 9 0 0118 0z"/&gt;&lt;/svg&gt;&lt;/div&gt;
&lt;div class="hx:w-full hx:min-w-0 hx:leading-7"&gt;
&lt;div class="hx:mt-6 hx:leading-7 hx:first:mt-0"&gt;This report is also available as a &lt;a href="http://www.vulnerability-lookup.org/files/news/2025/12/GPU_Efficiency_VLAI_Model_Training_2025.pdf"&gt;PDF&lt;/a&gt;.&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;Preface&lt;span class="hx:absolute hx:-mt-20" id="preface"&gt;&lt;/span&gt;
&lt;a href="#preface" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This document summarizes the benchmarking, training configuration, and performance results obtained while generating the &lt;strong&gt;Vulnerability Severity Classification&lt;/strong&gt; model across different GPU architectures throughout 2025.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;VLAI Vulnerability Severity Classification&lt;/strong&gt; model developed at CIRCL is regularly updated and shared on Hugging Face. It has been presented in:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Bonhomme, C., &amp;amp; Dulaunoy, A. (2025). &lt;em&gt;VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification&lt;/em&gt; (Version 1.4.0) [Computer software].&lt;br&gt;
&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;https://doi.org/10.48550/arXiv.2507.03607&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;All materials used to produce this technical report—including Matplotlib scripts, datasets, and other resources—are available in the Git repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/gpu-vuln-bench"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/gpu-vuln-bench&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Environments used for benchmarking&lt;span class="hx:absolute hx:-mt-20" id="environments-used-for-benchmarking"&gt;&lt;/span&gt;
&lt;a href="#environments-used-for-benchmarking" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;GPU Architectures&lt;span class="hx:absolute hx:-mt-20" id="gpu-architectures"&gt;&lt;/span&gt;
&lt;a href="#gpu-architectures" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The performance benchmarks were conducted on the GPU-accelerated systems described in the table 1.
Each environment varies in CPU architecture, GPU type, and memory capacity, enabling us to
evaluate model training efficiency across different hardware configurations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Table 1:&lt;/strong&gt; GPU-accelerated systems used for benchmarking in different environments.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Env&lt;/th&gt;
&lt;th&gt;CPU&lt;/th&gt;
&lt;th&gt;GPU&lt;/th&gt;
&lt;th&gt;RAM&lt;/th&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;64 (AMD EPYC 9124 16-Core Processor)&lt;/td&gt;
&lt;td&gt;2 × NVIDIA L40S&lt;/td&gt;
&lt;td&gt;251.5 GB&lt;/td&gt;
&lt;td&gt;CIRCL Server Lab (Luxembourg City)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;B&lt;/td&gt;
&lt;td&gt;224 (Intel Xeon Platinum 8480+)&lt;/td&gt;
&lt;td&gt;2 × NVIDIA H100 NVL&lt;/td&gt;
&lt;td&gt;2,014 GB&lt;/td&gt;
&lt;td&gt;LuxConnect Datacenter&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C&lt;/td&gt;
&lt;td&gt;224 (Intel Xeon Platinum 8480+)&lt;/td&gt;
&lt;td&gt;4 × NVIDIA L40S&lt;/td&gt;
&lt;td&gt;2,014 GB&lt;/td&gt;
&lt;td&gt;LuxConnect Datacenter&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Each environment was used to execute a series of experiments designed to measure the throughput,
memory utilization, and training time of the VLAI Vulnerability Severity Classification model.
The following sections provide a detailed summary and analysis of these experiments.&lt;/p&gt;
&lt;h3&gt;Framework Versions&lt;span class="hx:absolute hx:-mt-20" id="framework-versions"&gt;&lt;/span&gt;
&lt;a href="#framework-versions" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Main software and libraries used during the experiences:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Python:&lt;/strong&gt; 3.12.3&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Transformers:&lt;/strong&gt; 4.57.1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PyTorch:&lt;/strong&gt; 2.9.1+cu128&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Datasets:&lt;/strong&gt; 4.4.1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tokenizers:&lt;/strong&gt; 0.22.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Dataset&lt;span class="hx:absolute hx:-mt-20" id="dataset"&gt;&lt;/span&gt;
&lt;a href="#dataset" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The dataset used for training and evaluation is available on Hugging Face at the commit
&lt;a href="https://huggingface.co/datasets/CIRCL/vulnerability-scores/tree/2135755d8f42902de065d1ca30d800820b1e5cf1"target="_blank" rel="noopener"&gt;2135755d8f42902de065d1ca30d800820b1e5cf1&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://huggingface.co/datasets/CIRCL/vulnerability-scores"target="_blank" rel="noopener"&gt;https://huggingface.co/datasets/CIRCL/vulnerability-scores&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This is the updated version of the dataset referenced in &lt;code&gt;arXiv.2507.03607&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Dataset statistics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Number of rows: 642,080
&lt;ul&gt;
&lt;li&gt;Train split: 577,872&lt;/li&gt;
&lt;li&gt;Test split: 64,208&lt;/li&gt;
&lt;li&gt;ref: &lt;a href="https://huggingface.co/datasets/CIRCL/vulnerability-scores/commit/2135755d8f42902de065d1ca30d800820b1e5cf1"target="_blank" rel="noopener"&gt;commit 2135755d8f42902de065d1ca30d800820b1e5cf1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Downloaded size: 159 MB&lt;/li&gt;
&lt;li&gt;Auto-converted Parquet size: 159 MB&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The test split accounts for &lt;strong&gt;10%&lt;/strong&gt; of the dataset and can be configured in &lt;a href="https://github.com/vulnerability-lookup/VulnTrain"target="_blank" rel="noopener"&gt;VulnTrain&lt;/a&gt;
(&lt;a href="https://github.com/vulnerability-lookup/VulnTrain"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/VulnTrain&lt;/a&gt;).&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;VulnTrain is developed as part of the AIPITCH project and is integrated with Vulnerability-Lookup via &lt;strong&gt;ML-Gateway&lt;/strong&gt;—a FastAPI-based local server that loads one or more pre-trained NLP models at startup and exposes them through a clean, RESTful API for inference.&lt;br&gt;
For more details, see: &lt;a href="https://github.com/vulnerability-lookup/ML-Gateway"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/ML-Gateway&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This dataset is periodically updated with data collected with &lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Model Training&lt;span class="hx:absolute hx:-mt-20" id="model-training"&gt;&lt;/span&gt;
&lt;a href="#model-training" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Resulting models&lt;span class="hx:absolute hx:-mt-20" id="resulting-models"&gt;&lt;/span&gt;
&lt;a href="#resulting-models" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The main model is available on Hugging Face:&lt;br&gt;
&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base"target="_blank" rel="noopener"&gt;https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It is a fine-tuned version of &lt;a href="https://huggingface.co/roberta-base"target="_blank" rel="noopener"&gt;RoBERTa-base&lt;/a&gt; trained on the &lt;a href="https://huggingface.co/datasets/CIRCL/vulnerability-scores"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-scores&lt;/a&gt; dataset.&lt;br&gt;
Intermediate models are also available on Hugging Face and are versioned for reproducibility:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base-expA"target="_blank" rel="noopener"&gt;https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base-expA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base-expB"target="_blank" rel="noopener"&gt;https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base-expB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base-expC"target="_blank" rel="noopener"&gt;https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base-expC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The code of the trainer is available in the VulnTrain project.&lt;/p&gt;
&lt;h3&gt;Training Hyperparameters&lt;span class="hx:absolute hx:-mt-20" id="training-hyperparameters"&gt;&lt;/span&gt;
&lt;a href="#training-hyperparameters" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The following hyperparameters were used during training:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Learning rate:&lt;/strong&gt; &lt;code&gt;3e-05&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Per device Batch Size:&lt;/strong&gt; 8&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Seed:&lt;/strong&gt; &lt;code&gt;42&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Optimizer:&lt;/strong&gt; &lt;code&gt;ADAMW_TORCH_FUSED&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scheduler:&lt;/strong&gt; &lt;code&gt;linear&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Epochs:&lt;/strong&gt; &lt;code&gt;5&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For a RoBERTa model, the default batch size per device we chose is &lt;strong&gt;8&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;RoBERTa-base is a medium-sized Transformer model (approx. 125 million parameters). A batch size of 8 per device is a standard, conservative choice that is un likely to cause Out-of-Memory (OOM) errors on most modern GPUs (like NVIDIA V100, A100, or even modern consumer cards like the RTX 3080/4080) for typical sequence lengths (e.g., 128 or 256 tokens).&lt;/p&gt;
&lt;p&gt;&lt;code&gt;3e-05&lt;/code&gt; is a standard and safe learning rate for fine-tuning RoBERTa, with the optimizer using its default settings.&lt;/p&gt;
&lt;h4&gt;A quick note on epochs and batches&lt;span class="hx:absolute hx:-mt-20" id="a-quick-note-on-epochs-and-batches"&gt;&lt;/span&gt;
&lt;a href="#a-quick-note-on-epochs-and-batches" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;A &lt;strong&gt;batch&lt;/strong&gt; is a subset of the training data processed together in &lt;strong&gt;one forward and backward pass&lt;/strong&gt;, producing gradients that update the model weights.&lt;br&gt;
The batch size is the number of samples in that batch.&lt;/p&gt;
&lt;p&gt;An &lt;strong&gt;epoch&lt;/strong&gt; is one full pass over the entire training dataset.&lt;br&gt;
Since the dataset is divided into batches, an epoch consists of multiple steps, where each step processes one batch and updates the model weights.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;effective batch size&lt;/strong&gt; (batch size × number of GPUs) influences training dynamics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Larger effective batches produce more stable gradients, require fewer optimization steps per epoch, and often converge faster.&lt;/li&gt;
&lt;li&gt;Smaller batches introduce noise in the gradients, which can help escape poor local minima and improve generalization, but each epoch takes longer.&lt;/li&gt;
&lt;li&gt;The impact on generalization also depends on using an appropriate learning rate.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;RoBERTa often benefits from slightly larger batches. For example, using a batch of 32 samples per step can reduce gradient noise and stabilize learning, leading to quicker convergence.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Figure 1:&lt;/strong&gt; Number of GPUs / Batch Size - Illustration 1&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/gpu-batch-size-example-1.png" alt="# GPUs / Batch Size - Illustration 1" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Figure 2:&lt;/strong&gt; Number of GPUs / Batch Size - Illustration 2&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/gpu-batch-size-example-2.png" alt="# GPUs / Batch Size - Illustration 2" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;Each colored rectangle represents a single training step, corresponding to one processed batch.
An epoch ends once &lt;code&gt;steps_per_epoch&lt;/code&gt; steps have been completed.&lt;/p&gt;
&lt;p&gt;In our case, the training split contains 577,872 samples. The visualizations use a simplified view to illustrate the concepts more clearly for learning purposes.
They illustrate how batch size, number of GPUs, and dataset size affect the number of training steps per epoch.&lt;/p&gt;
&lt;h3&gt;Training results&lt;span class="hx:absolute hx:-mt-20" id="training-results"&gt;&lt;/span&gt;
&lt;a href="#training-results" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Environment&lt;/th&gt;
&lt;th&gt;Final Loss&lt;/th&gt;
&lt;th&gt;Final Accuracy&lt;/th&gt;
&lt;th&gt;Epochs to Converge&lt;/th&gt;
&lt;th&gt;Batch Size&lt;/th&gt;
&lt;th&gt;Steps per Epoch&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;0.2537&lt;/td&gt;
&lt;td&gt;0.8232&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;29470&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;B&lt;/td&gt;
&lt;td&gt;0.2801&lt;/td&gt;
&lt;td&gt;0.8230&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;29470&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C&lt;/td&gt;
&lt;td&gt;0.3793&lt;/td&gt;
&lt;td&gt;0.8173&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;32&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;14735&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Table 2:&lt;/strong&gt; Final training results for the different environments.&lt;/p&gt;
&lt;p&gt;Results in terms of &lt;strong&gt;loss&lt;/strong&gt; and &lt;strong&gt;accuracy&lt;/strong&gt; are very similar, regardless of the system used.&lt;br&gt;
Each experiment produced slightly different rankings, but the differences are minimal.&lt;/p&gt;
&lt;p&gt;The samples per epoch is the same in each environments: 577,872. Wich corresponds to 10 per cent of the
dataset .&lt;/p&gt;
&lt;h4&gt;Environment A&lt;span class="hx:absolute hx:-mt-20" id="environment-a"&gt;&lt;/span&gt;
&lt;a href="#environment-a" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Theoretically, &lt;code&gt;samples_per_epoch&lt;/code&gt; should match the number of samples in the training split (577,872),
but our trainer filters out entries with missing or unknown severity labels.
As previously explained an &lt;strong&gt;epoch&lt;/strong&gt; is one full pass over the entire training dataset.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: right"&gt;Training Loss&lt;/th&gt;
&lt;th style="text-align: center"&gt;Epoch&lt;/th&gt;
&lt;th style="text-align: right"&gt;Step&lt;/th&gt;
&lt;th style="text-align: right"&gt;Validation Loss&lt;/th&gt;
&lt;th style="text-align: right"&gt;Accuracy&lt;/th&gt;
&lt;th style="text-align: right"&gt;steps_per_epoch&lt;/th&gt;
&lt;th style="text-align: right"&gt;samples_per_epoch&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.4999&lt;/td&gt;
&lt;td style="text-align: center"&gt;1.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;&lt;strong&gt;29470&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.6657&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7290&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.5279&lt;/td&gt;
&lt;td style="text-align: center"&gt;2.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;58940&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5911&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7685&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.4775&lt;/td&gt;
&lt;td style="text-align: center"&gt;3.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;88410&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5392&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7961&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.3753&lt;/td&gt;
&lt;td style="text-align: center"&gt;4.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;117880&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5125&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.8122&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.2537&lt;/td&gt;
&lt;td style="text-align: center"&gt;5.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;147350&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5169&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.8232&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Table 3:&lt;/strong&gt; Training results for an experiment with environment A&lt;/p&gt;
&lt;h4&gt;Environment B&lt;span class="hx:absolute hx:-mt-20" id="environment-b"&gt;&lt;/span&gt;
&lt;a href="#environment-b" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: right"&gt;Training Loss&lt;/th&gt;
&lt;th style="text-align: center"&gt;Epoch&lt;/th&gt;
&lt;th style="text-align: right"&gt;Step&lt;/th&gt;
&lt;th style="text-align: right"&gt;Validation Loss&lt;/th&gt;
&lt;th style="text-align: right"&gt;Accuracy&lt;/th&gt;
&lt;th style="text-align: right"&gt;steps_per_epoch&lt;/th&gt;
&lt;th style="text-align: right"&gt;samples_per_epoch&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.5379&lt;/td&gt;
&lt;td style="text-align: center"&gt;1.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;&lt;strong&gt;29470&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.6573&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7358&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.5714&lt;/td&gt;
&lt;td style="text-align: center"&gt;2.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;58940&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5810&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7710&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.4636&lt;/td&gt;
&lt;td style="text-align: center"&gt;3.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;88410&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5412&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7918&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.4738&lt;/td&gt;
&lt;td style="text-align: center"&gt;4.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;117880&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5098&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.8131&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.2801&lt;/td&gt;
&lt;td style="text-align: center"&gt;5.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;147350&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5175&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.8230&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Table 4:&lt;/strong&gt; Training results for an experiment with environment B&lt;/p&gt;
&lt;h4&gt;Environment C&lt;span class="hx:absolute hx:-mt-20" id="environment-c"&gt;&lt;/span&gt;
&lt;a href="#environment-c" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: right"&gt;Training Loss&lt;/th&gt;
&lt;th style="text-align: center"&gt;Epoch&lt;/th&gt;
&lt;th style="text-align: right"&gt;Step&lt;/th&gt;
&lt;th style="text-align: right"&gt;Validation Loss&lt;/th&gt;
&lt;th style="text-align: right"&gt;Accuracy&lt;/th&gt;
&lt;th style="text-align: right"&gt;steps_per_epoch&lt;/th&gt;
&lt;th style="text-align: right"&gt;samples_per_epoch&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.6270&lt;/td&gt;
&lt;td style="text-align: center"&gt;1.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;&lt;strong&gt;14735&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.6594&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7298&lt;/td&gt;
&lt;td style="text-align: right"&gt;14735.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.5675&lt;/td&gt;
&lt;td style="text-align: center"&gt;2.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;29470&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5780&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7693&lt;/td&gt;
&lt;td style="text-align: right"&gt;14735.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.4690&lt;/td&gt;
&lt;td style="text-align: center"&gt;3.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;44205&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5363&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.7930&lt;/td&gt;
&lt;td style="text-align: right"&gt;14735.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.4373&lt;/td&gt;
&lt;td style="text-align: center"&gt;4.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;58940&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5069&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.8107&lt;/td&gt;
&lt;td style="text-align: right"&gt;14735.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: right"&gt;0.3793&lt;/td&gt;
&lt;td style="text-align: center"&gt;5.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;73675&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.5071&lt;/td&gt;
&lt;td style="text-align: right"&gt;0.8173&lt;/td&gt;
&lt;td style="text-align: right"&gt;14735.0&lt;/td&gt;
&lt;td style="text-align: right"&gt;471520.0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Table 5:&lt;/strong&gt; Training results for an experiment with environment C&lt;/p&gt;
&lt;p&gt;Note that &lt;/p&gt;
&lt;span class="katex-display"&gt;&lt;span class="katex"&gt;&lt;span class="katex-mathml"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML" display="block"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mn&gt;147350&lt;/mn&gt;&lt;mi mathvariant="normal"&gt;/&lt;/mi&gt;&lt;mn&gt;2&lt;/mn&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;73675&lt;/mn&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;147350 / 2 = 73675&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;span class="katex-html" aria-hidden="true"&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:1em;vertical-align:-0.25em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;147350/2&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;span class="mrel"&gt;=&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:0.6444em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;73675&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;h4&gt;Comparisons&lt;span class="hx:absolute hx:-mt-20" id="comparisons"&gt;&lt;/span&gt;
&lt;a href="#comparisons" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/cumulative-samples-steps.png" alt="Cumulative Samples vs Steps" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;A common rule of thumb is the &lt;strong&gt;linear scaling rule&lt;/strong&gt;: when the effective batch size is doubled, the learning rate is also doubled.&lt;br&gt;
This behavior is confirmed in all of our experiments.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/accuracy-per-epoch.png" alt="Validation Accuracy per Epoch" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The chart shows the validation accuracy per epoch for the various experiments with the environments A, B, and C.&lt;br&gt;
All experiments exhibit very similar accuracy trends.&lt;br&gt;
Experiments in environment C reaches higher accuracy more quickly in the early epochs, reflecting faster convergence per epoch due to a larger effective batch size (more GPUs × batch per device).&lt;br&gt;
By the final epoch, all experiments achieve &lt;strong&gt;comparable accuracy&lt;/strong&gt; (~0.82), indicating consistent model performance across the different setups.&lt;/p&gt;
&lt;h3&gt;Key Observations&lt;span class="hx:absolute hx:-mt-20" id="key-observations"&gt;&lt;/span&gt;
&lt;a href="#key-observations" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;More GPUs → larger effective batch → fewer steps per epoch&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Example:
&lt;ul&gt;
&lt;li&gt;4 GPUs × 256 samples → 1024 samples/step → fewer steps to process the full dataset&lt;/li&gt;
&lt;li&gt;2 GPUs × 256 samples → 612 samples/step → more steps to process the same dataset&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Larger batch size per device → fewer steps per epoch&lt;/strong&gt;, but each step processes more data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Epoch duration&lt;/strong&gt; is proportional to number of steps × time per step, so increasing GPUs or batch size reduces total training time per epoch.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Figure 1 and 2 make it easier to understand why Exp C (4 GPUs, batch size 8 per device → effective batch 32) completes fewer steps per epoch and thus runs faster per epoch than Exp A/B (2 GPUs, effective batch 16), even though the dataset and model are identical.&lt;/p&gt;
&lt;h2&gt;Benchmark Comparisons Across Different Environments&lt;span class="hx:absolute hx:-mt-20" id="benchmark-comparisons-across-different-environments"&gt;&lt;/span&gt;
&lt;a href="#benchmark-comparisons-across-different-environments" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Duration&lt;span class="hx:absolute hx:-mt-20" id="duration"&gt;&lt;/span&gt;
&lt;a href="#duration" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/duration_comparison.png" alt="Duration" loading="lazy" /&gt;&lt;/p&gt;
&lt;h3&gt;Energy&lt;span class="hx:absolute hx:-mt-20" id="energy"&gt;&lt;/span&gt;
&lt;a href="#energy" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/energy_breakdown_comparison.png" alt="Energy breakdown comparison" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/energy_consumption_comparison.png" alt="Energy consumption comparison" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/radar_energy_comparison.png" alt="CPU/GPU/RAM Energy breakdown" loading="lazy" /&gt;&lt;/p&gt;
&lt;h3&gt;Emissions&lt;span class="hx:absolute hx:-mt-20" id="emissions"&gt;&lt;/span&gt;
&lt;a href="#emissions" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/emissions_comparison.png" alt="Emissions comparison" loading="lazy" /&gt;&lt;/p&gt;
&lt;h3&gt;GPU Power&lt;span class="hx:absolute hx:-mt-20" id="gpu-power"&gt;&lt;/span&gt;
&lt;a href="#gpu-power" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/gpu_power_comparison.png" alt="GPU power" loading="lazy" /&gt;&lt;/p&gt;
&lt;h3&gt;Energy vs. Duration&lt;span class="hx:absolute hx:-mt-20" id="energy-vs-duration"&gt;&lt;/span&gt;
&lt;a href="#energy-vs-duration" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/scatter_energy_vs_duration.png" alt="Energy vs duration" loading="lazy" /&gt;&lt;/p&gt;
&lt;h3&gt;GPU Power vs. Duration&lt;span class="hx:absolute hx:-mt-20" id="gpu-power-vs-duration"&gt;&lt;/span&gt;
&lt;a href="#gpu-power-vs-duration" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/scatter_gpu_power_vs_duration.png" alt="GPU power vs duration" loading="lazy" /&gt;&lt;/p&gt;
&lt;h3&gt;GPU Power vs. Energy&lt;span class="hx:absolute hx:-mt-20" id="gpu-power-vs-energy"&gt;&lt;/span&gt;
&lt;a href="#gpu-power-vs-energy" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/scatter_gpu_power_vs_energy.png" alt="GPU power vs energy" loading="lazy" /&gt;&lt;/p&gt;
&lt;h3&gt;Conclusion&lt;span class="hx:absolute hx:-mt-20" id="conclusion"&gt;&lt;/span&gt;
&lt;a href="#conclusion" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;From our perspective, &lt;strong&gt;Environment C&lt;/strong&gt; offers the best balance of performance and energy efficiency.
The quality of the resulting model is not significantly affected by these small variations in batch size, and may in fact &lt;strong&gt;remain completely unchanged&lt;/strong&gt;. We plan to explore additional configurations in the future using our new equipment.&lt;/p&gt;
&lt;h2&gt;Evolution of Experiments in Environment A&lt;span class="hx:absolute hx:-mt-20" id="evolution-of-experiments-in-environment-a"&gt;&lt;/span&gt;
&lt;a href="#evolution-of-experiments-in-environment-a" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;We have been collecting data since February 2025 in &lt;strong&gt;Environment A&lt;/strong&gt;, which is equipped with &lt;strong&gt;2 × NVIDIA L40S GPUs&lt;/strong&gt;.
The charts below illustrate the evolution of our experiments over the course of the year.
(Environments B and C are too recent to provide meaningful data at this time.)&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/duration_with_dataset_evolution.png" alt="Evolution of the duration" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/energy_consumed_with_dataset_evolution.png" alt="Evolution of the energy consumption" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/gpu_power_with_dataset_evolution.png" alt="Evolution of the GPU power used" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The workload did not change enough to explain the summer peak:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The dataset size shows a nearly linear and steady growth.&lt;/li&gt;
&lt;li&gt;We did not change the training hyperparameters or the base model (model size) in this configuration.&lt;/li&gt;
&lt;li&gt;No changes were made to the GPU configuration.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Our hypothesis is &lt;strong&gt;thermal throttling&lt;/strong&gt; and &lt;strong&gt;cooling overhead&lt;/strong&gt;.&lt;br&gt;
CodeCarbon estimates total energy consumption using the &lt;strong&gt;PUE (Power Usage Effectiveness)&lt;/strong&gt; of the environment.&lt;br&gt;
If PUE increases during summer due to higher cooling requirements, the estimated energy usage rises, even if the GPU workload remains identical.&lt;/p&gt;
&lt;p&gt;When ambient temperatures increase, hardware may:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;throttle its operating frequency,&lt;/li&gt;
&lt;li&gt;reduce performance,&lt;/li&gt;
&lt;li&gt;complete the same training steps over a longer duration.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As a result, even if instantaneous power consumption remains similar, the overall job duration increases, which leads to a higher total energy consumption (more Joules).&lt;/p&gt;
&lt;p&gt;It must be noted that &lt;strong&gt;Environment A is located in the CIRCL Server Lab in Luxembourg City&lt;/strong&gt;, where temperature is &lt;strong&gt;not controlled&lt;/strong&gt; as strictly as in a datacenter.&lt;/p&gt;
&lt;p&gt;We will monitor temperature and environmental metrics in future experiments to quantify these effects more precisely.&lt;/p&gt;
&lt;h2&gt;Future Works&lt;span class="hx:absolute hx:-mt-20" id="future-works"&gt;&lt;/span&gt;
&lt;a href="#future-works" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The acquisition of our new equipment will allow us to conduct more experiments across a variety of configurations, enabling larger and more complex model training, which could have a greater impact (negative or positive) on model accuracy.&lt;/p&gt;
&lt;p&gt;As a first demonstration, we recently developed a text generation model designed to assist in writing vulnerability descriptions.
This is a fine-tuned version of GPT-2 XL, the 1.5B parameter variant of GPT-2.
The model is available here:
&lt;a href="https://huggingface.co/CIRCL/vulnerability-description-generation-gpt2-xl"target="_blank" rel="noopener"&gt;https://huggingface.co/CIRCL/vulnerability-description-generation-gpt2-xl&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The model was trained in Environment C over approximately 34 hours.
Training in Environment A was not feasible, even with the standard GPT-2 model, due to GPU memory limitations.&lt;/p&gt;
&lt;p&gt;In addition, we plan to improve our CWE classification model using the vulnerability patches we have collected
(&lt;a href="https://huggingface.co/datasets/CIRCL/vulnerability-cwe-patch"target="_blank" rel="noopener"&gt;https://huggingface.co/datasets/CIRCL/vulnerability-cwe-patch&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;We also plan to experiment with a RAG (Retrieval-Augmented Generation) system, which combines retrieval from a knowledge base with generative models to produce answers. This approach is particularly suited for domain-specific information, in our case software vulnerabilities.
Alternatively, we may explore a Question-Answering (QA) system, focused on providing factual answers directly from our dataset.&lt;/p&gt;
&lt;h2&gt;Resources&lt;span class="hx:absolute hx:-mt-20" id="resources"&gt;&lt;/span&gt;
&lt;a href="#resources" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Related to CodeCarbon&amp;rsquo;s RAM Energy Calculation&lt;span class="hx:absolute hx:-mt-20" id="related-to-codecarbons-ram-energy-calculation"&gt;&lt;/span&gt;
&lt;a href="#related-to-codecarbons-ram-energy-calculation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;CodeCarbon primarily calculates the energy used by &lt;strong&gt;RAM&lt;/strong&gt; through a &lt;strong&gt;power consumption model&lt;/strong&gt; based on estimations, rather than direct hardware measurement, unless specific system features are available.&lt;/p&gt;
&lt;p&gt;The power estimation for a &amp;ldquo;large server&amp;rdquo; is approximately 40W (using 8x128GB DIMMs with high efficiency scaling).&lt;/p&gt;
&lt;p&gt;Reference: &lt;a href="https://mlco2.github.io/codecarbon/methodology.html#ram"target="_blank" rel="noopener"&gt;https://mlco2.github.io/codecarbon/methodology.html#ram&lt;/a&gt;&lt;/p&gt;
&lt;h4&gt;Estimation Methodology&lt;span class="hx:absolute hx:-mt-20" id="estimation-methodology"&gt;&lt;/span&gt;
&lt;a href="#estimation-methodology" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;The default method relies on a fixed power consumption value per installed RAM module (DIMM):&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Fixed Power per DIMM:&lt;/strong&gt; A standardized, average power consumption value is assigned to each RAM module.
&lt;ul&gt;
&lt;li&gt;For &lt;strong&gt;x86 Systems&lt;/strong&gt; (most standard laptops/desktops), this is typically set at &lt;strong&gt;5 Watts&lt;/strong&gt; per DIMM.&lt;/li&gt;
&lt;li&gt;For &lt;strong&gt;ARM Systems&lt;/strong&gt; (e.g., Raspberry Pi), a lower base power, like &lt;strong&gt;1.5W&lt;/strong&gt; per DIMM, or a constant of &lt;strong&gt;3W&lt;/strong&gt;, is used.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Counting RAM Modules:&lt;/strong&gt; CodeCarbon attempts to determine the &lt;strong&gt;number of installed RAM modules (DIMMs)&lt;/strong&gt; on the system by querying the operating system.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Total Power Calculation:&lt;/strong&gt; The estimated total RAM power is calculated by multiplying these two values:
&lt;span class="katex"&gt;&lt;span class="katex-mathml"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;RAM Power (Watts)&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;Fixed Power per DIMM&lt;/mtext&gt;&lt;mo&gt;×&lt;/mo&gt;&lt;mtext&gt;Number of RAM Slots Used&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;\text{RAM Power (Watts)} = \text{Fixed Power per DIMM} \times \text{Number of RAM Slots Used}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;span class="katex-html" aria-hidden="true"&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:1em;vertical-align:-0.25em;"&gt;&lt;/span&gt;&lt;span class="mord text"&gt;&lt;span class="mord"&gt;RAM Power (Watts)&lt;/span&gt;&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;span class="mrel"&gt;=&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"&gt;&lt;/span&gt;&lt;span class="mord text"&gt;&lt;span class="mord"&gt;Fixed Power per DIMM&lt;/span&gt;&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;span class="mbin"&gt;×&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:0.6944em;"&gt;&lt;/span&gt;&lt;span class="mord text"&gt;&lt;span class="mord"&gt;Number of RAM Slots Used&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scaling (for Servers):&lt;/strong&gt; For systems with many DIMMs (e.g., servers with 8+ slots), a scaling factor is applied to reduce the power assigned to each additional DIMM, acknowledging that power consumption doesn&amp;rsquo;t increase strictly linearly in large configurations.&lt;/li&gt;
&lt;/ol&gt;
&lt;h4&gt;Energy Calculation&lt;span class="hx:absolute hx:-mt-20" id="energy-calculation"&gt;&lt;/span&gt;
&lt;a href="#energy-calculation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Once the estimated &lt;strong&gt;RAM Power&lt;/strong&gt; (in Watts) is determined, the &lt;strong&gt;Energy Consumed&lt;/strong&gt; (in kilowatt-hours, or kWh) is calculated based on the duration of the code execution:&lt;/p&gt;
&lt;span class="katex-display"&gt;&lt;span class="katex"&gt;&lt;span class="katex-mathml"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML" display="block"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;Energy (kWh)&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mfrac&gt;&lt;mrow&gt;&lt;mtext&gt;Power (Watts)&lt;/mtext&gt;&lt;mo&gt;×&lt;/mo&gt;&lt;mtext&gt;Time (hours)&lt;/mtext&gt;&lt;/mrow&gt;&lt;mn&gt;1000&lt;/mn&gt;&lt;/mfrac&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;\text{Energy (kWh)} = \frac{\text{Power (Watts)} \times \text{Time (hours)}}{1000}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;span class="katex-html" aria-hidden="true"&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:1em;vertical-align:-0.25em;"&gt;&lt;/span&gt;&lt;span class="mord text"&gt;&lt;span class="mord"&gt;Energy (kWh)&lt;/span&gt;&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;span class="mrel"&gt;=&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:2.113em;vertical-align:-0.686em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mopen nulldelimiter"&gt;&lt;/span&gt;&lt;span class="mfrac"&gt;&lt;span class="vlist-t vlist-t2"&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:1.427em;"&gt;&lt;span style="top:-2.314em;"&gt;&lt;span class="pstrut" style="height:3em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mord"&gt;1000&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="top:-3.23em;"&gt;&lt;span class="pstrut" style="height:3em;"&gt;&lt;/span&gt;&lt;span class="frac-line" style="border-bottom-width:0.04em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="top:-3.677em;"&gt;&lt;span class="pstrut" style="height:3em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mord text"&gt;&lt;span class="mord"&gt;Power (Watts)&lt;/span&gt;&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;span class="mbin"&gt;×&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;span class="mord text"&gt;&lt;span class="mord"&gt;Time (hours)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="vlist-s"&gt;​&lt;/span&gt;&lt;/span&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:0.686em;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="mclose nulldelimiter"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;h4&gt;Direct Measurement Alternative&lt;span class="hx:absolute hx:-mt-20" id="direct-measurement-alternative"&gt;&lt;/span&gt;
&lt;a href="#direct-measurement-alternative" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;On Linux systems, CodeCarbon offers a more accurate method with the &lt;strong&gt;Intel Running Average Power Limit (RAPL)&lt;/strong&gt; interface.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If the &lt;code&gt;rapl_include_dram&lt;/code&gt; parameter is set to &lt;code&gt;True&lt;/code&gt;, CodeCarbon will attempt to use the &lt;strong&gt;direct power measurement&lt;/strong&gt; for the DRAM (memory subsystem) provided by RAPL, overriding the fixed power estimation model. This method offers the most precise consumption data when available.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Reference: &lt;a href="https://mlco2.github.io/codecarbon/parameters.html"target="_blank" rel="noopener"&gt;https://mlco2.github.io/codecarbon/parameters.html&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Related to CodeCarbon&amp;rsquo;s GPU Energy Calculation&lt;span class="hx:absolute hx:-mt-20" id="related-to-codecarbons-gpu-energy-calculation"&gt;&lt;/span&gt;
&lt;a href="#related-to-codecarbons-gpu-energy-calculation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The energy consumption is tracked using &lt;code&gt;nvidia-ml-py&lt;/code&gt;library.&lt;/p&gt;
&lt;p&gt;Reference: &lt;a href="https://mlco2.github.io/codecarbon/methodology.html#gpu"target="_blank" rel="noopener"&gt;https://mlco2.github.io/codecarbon/methodology.html#gpu&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Environmental Considerations&lt;span class="hx:absolute hx:-mt-20" id="environmental-considerations"&gt;&lt;/span&gt;
&lt;a href="#environmental-considerations" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Our server room is hosted in LuxConnect’s data centers, which are powered entirely by renewable energy (&lt;a href="https://www.luxconnect.lu/infrastructure"target="_blank" rel="noopener"&gt;https://www.luxconnect.lu/infrastructure&lt;/a&gt;).&lt;/p&gt;
&lt;h3&gt;Litterature&lt;span class="hx:absolute hx:-mt-20" id="litterature"&gt;&lt;/span&gt;
&lt;a href="#litterature" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&amp;ldquo;Natural Language Processing with Transformers&amp;rdquo;&lt;br&gt;
&lt;a href="https://www.librarything.com/work/27807959/281493045"target="_blank" rel="noopener"&gt;https://www.librarything.com/work/27807959/281493045&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;How AI Works: From Sorcery to Science&amp;rdquo;&lt;br&gt;
&lt;a href="https://www.librarything.com/work/31127745/287620374"target="_blank" rel="noopener"&gt;https://www.librarything.com/work/31127745/287620374&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Bonhomme, C., &amp;amp; Dulaunoy, A. (2025). &lt;em&gt;VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification&lt;/em&gt; (Version 1.4.0) [Computer software].&lt;br&gt;
&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;https://doi.org/10.48550/arXiv.2507.03607&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Feedback&lt;span class="hx:absolute hx:-mt-20" id="feedback"&gt;&lt;/span&gt;
&lt;a href="#feedback" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Feel free to share your feedback at &lt;a href="mailto:info@circl.lu"&gt;info@circl.lu&lt;/a&gt; or publicly:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/gpu-vuln-bench/issues"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/gpu-vuln-bench/issues&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/europe.png" alt="EU Funding" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.science.nask.pl/en/research-areas/projects/12456"target="_blank" rel="noopener"&gt;AIPITCH&lt;/a&gt; aims to create advanced artificial intelligence-based tools supporting key operational services in cyber defense.
These include technologies for early threat detection, automatic malware classification, and improvement of analytical processes through the integration of Large Language Models (LLM).
The project has the potential to set new standards in the cybersecurity industry.&lt;/p&gt;
&lt;p&gt;The project leader is NASK National Research Institute. The international consortium includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CIRCL (Computer Incident Response Center Luxembourg), Luxembourg&lt;/li&gt;
&lt;li&gt;The Shadowserver Foundation, Netherlands&lt;/li&gt;
&lt;li&gt;NCBJ (National Centre for Nuclear Research), Poland&lt;/li&gt;
&lt;li&gt;ABI LAB (Centre of Research and Innovation for Banks), Italy&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Cybersecurity Competence Centre.
Neither the European Union nor the European Cybersecurity Competence Centre can be held responsible for them.&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.19.0 released</title><link>http://www.vulnerability-lookup.org/2025/12/09/vulnerability-lookup-2-19-0/</link><pubDate>Tue, 09 Dec 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/12/09/vulnerability-lookup-2-19-0/</guid><description>
&lt;p&gt;We’re delighted to announce the release of &lt;strong&gt;Vulnerability-Lookup 2.19.0&lt;/strong&gt;!&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;GCVE: Global CVE Allocation System&lt;span class="hx:absolute hx:-mt-20" id="gcve-global-cve-allocation-system"&gt;&lt;/span&gt;
&lt;a href="#gcve-global-cve-allocation-system" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;We’re pleased to announce the publication of:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gcve.eu/bcp/gcve-bcp-02/"target="_blank" rel="noopener"&gt;GCVE-BCP-02 – Practical Guide to Vulnerability Handling and Disclosure&lt;/a&gt;, and&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gcve.eu/bcp/gcve-bcp-04/"target="_blank" rel="noopener"&gt;GCVE-BCP-04 - Recommendations and Best Practices for ID Allocation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This Best Current Practice document GCVE-BCP-02 provides actionable guidance for organisations,
researchers, and GCVE Numbering Authorities (GNAs) on managing and disclosing
vulnerabilities effectively, both &lt;strong&gt;within the GCVE ecosystem and beyond&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Vulnerability-Lookup &lt;strong&gt;fully supports&lt;/strong&gt; these best practices for vulnerability disclosure,
helping to promote responsible and effective handling of security issues.&lt;/p&gt;
&lt;h3&gt;Graphical improvements&lt;span class="hx:absolute hx:-mt-20" id="graphical-improvements"&gt;&lt;/span&gt;
&lt;a href="#graphical-improvements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Added Credits section for CVE v5 format (used by GCVE) and the OpenSSF Malicious Packages.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/686e518"target="_blank" rel="noopener"&gt;686e518&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3b39016"target="_blank" rel="noopener"&gt;3b39016&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7e9bf4f"target="_blank" rel="noopener"&gt;7e9bf4f&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Show CVE description on hover in /recent page (and for the card box of the index page). &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/289"target="_blank" rel="noopener"&gt;#289&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Many templates have been improved, including the vulnerability detail page, the recent vulnerabilities list,
severity score displays, and all HTML tables, allowing more information to be shown while keeping the interface clean and user-friendly.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Tooltips for Bootstrap cardboxes&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/tooltip-cardbox.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/tooltip-cardbox.png" alt="Tooltips for Bootstrap cardboxes" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Tooltips for lists of recent vulnerabilities&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/tooltip-recent-list.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/tooltip-recent-list.png" alt="Tooltips for lists of recent vulnerabilities" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;New Credits section&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/credits.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/credits.png" alt="New credits section" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Credits for the OpenSSF Malicious Packages&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/credits-ossf.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/credits-ossf.png" alt="Credits for the OpenSSF Malicious Packages" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;chg: [website] Reorganized and improved all Jinja filters especially the filters related to the parsing of CVE data.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f912ef4"target="_blank" rel="noopener"&gt;f912ef4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Improved the display of the severity related information for CVE and GitHub sources in the /recent page.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/629dc7a"target="_blank" rel="noopener"&gt;629dc7a&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [website] New layout for severity implemented for PySec advisories.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/74387cd"target="_blank" rel="noopener"&gt;74387cd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [website] Added VLAI Severity score for PySec advisories.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3cfcc8d"target="_blank" rel="noopener"&gt;3cfcc8d&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [website] Extract and display credits from OSSF Malicious Packages sources.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3b39016"target="_blank" rel="noopener"&gt;3b39016&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Improved display of various tables.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/88b73f1"target="_blank" rel="noopener"&gt;88b73f1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [website] Display more data in the vulnerability evolution charts. The growth is now displayed in a tooltip box.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/b986dd3"target="_blank" rel="noopener"&gt;b986dd3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;fix: [backend] Remove notifications of users to be deleted.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3ad413f"target="_blank" rel="noopener"&gt;3ad413f&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [templates] Fixed a display issue for Tailscale ids.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ef8a4a8"target="_blank" rel="noopener"&gt;ef8a4a8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [templates] Handle single object case for the references section of record from the JVNDB.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f36689b"target="_blank" rel="noopener"&gt;f36689b&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Security&lt;span class="hx:absolute hx:-mt-20" id="security"&gt;&lt;/span&gt;
&lt;a href="#security" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;fix: [security] Unconfirm user accounts when their email address changes and send a password-reset token to the original email.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/46f30a0"target="_blank" rel="noopener"&gt;46f30a0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [security] Remove all items from the session dict on logout
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e2c54f7"target="_blank" rel="noopener"&gt;e2c54f7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [security] Regenerate session ID after a user updates their password.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2403fa6"target="_blank" rel="noopener"&gt;2403fa6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [security] Updating the password now requires the user to provide the current password.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a902f91"target="_blank" rel="noopener"&gt;a902f91&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [security] Sanitize related_vulnerabilities field of bundles (in backend) and avoid injecting raw HTML when building the DOM (in frontend) when displaying.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1811ef9"target="_blank" rel="noopener"&gt;1811ef9&lt;/a&gt; - &lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0035"target="_blank" rel="noopener"&gt;GCVE-1-2025-0035&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [security] All state changing endpoints are now using POST HTTP requests with a CSRF token.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a6c568d"target="_blank" rel="noopener"&gt;a6c568d&lt;/a&gt; - &lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0034"target="_blank" rel="noopener"&gt;GCVE-1-2025-0034&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;fix: [security] The number of failed OTP attemprs is now recorded. The user account is blocked after 5 attempts. Admins have the possibility to monitor failed 2FA via the admin panel (list of users).
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/113b1fe"target="_blank" rel="noopener"&gt;113b1fe&lt;/a&gt; - &lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0033"target="_blank" rel="noopener"&gt;GCVE-1-2025-0033&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.19.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.19.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
We appreciate your feedback!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - November 2025</title><link>http://www.vulnerability-lookup.org/2025/12/03/vulnerability-report-november-2025/</link><pubDate>Wed, 03 Dec 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/12/03/vulnerability-report-november-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for November 2025, based on sightings collected from various sources,
including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, Metasploit, and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The most frequently sighted vulnerability in November was &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-64446"target="_blank" rel="noopener"&gt;CVE-2025-64446&lt;/a&gt; (105 sightings), a Critical-severity vulnerability in Fortinet FortiWeb. Fortinet featured prominently, with a second FortiWeb vulnerability, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58034"target="_blank" rel="noopener"&gt;CVE-2025-58034&lt;/a&gt; (High severity), also in the top 10.&lt;/p&gt;
&lt;p&gt;Other critical vulnerabilities in the top 10 include &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt; in Microsoft Windows Server 2019 (88 sightings) and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61757"target="_blank" rel="noopener"&gt;CVE-2025-61757&lt;/a&gt; in Oracle Corporation Identity Manager (67 sightings). The list also features a highly sighted vulnerability in Samsung Mobile Devices (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21042"target="_blank" rel="noopener"&gt;CVE-2025-21042&lt;/a&gt;), a High-severity flaw in Google Chrome (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13223"target="_blank" rel="noopener"&gt;CVE-2025-13223&lt;/a&gt;), and an older but still active vulnerability in Cisco IOS XE Software (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-20198"target="_blank" rel="noopener"&gt;CVE-2023-20198&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;November saw 11 new entries added to the CISA Known Exploited Vulnerabilities catalog, highlighting actively exploited threats. Notable additions include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-64446"target="_blank" rel="noopener"&gt;CVE-2025-64446&lt;/a&gt; and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58034"target="_blank" rel="noopener"&gt;CVE-2025-58034&lt;/a&gt;: Fortinet FortiWeb&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21042"target="_blank" rel="noopener"&gt;CVE-2025-21042&lt;/a&gt;: Samsung Mobile Devices&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13223"target="_blank" rel="noopener"&gt;CVE-2025-13223&lt;/a&gt;: Google Chrome&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9242"target="_blank" rel="noopener"&gt;CVE-2025-9242&lt;/a&gt;: A Critical vulnerability in WatchGuard Fireware OS&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;No new entries were added to the ENISA KEV catalog in November.&lt;/p&gt;
&lt;p&gt;The report also details vulnerabilities that have reserved CVE IDs but have limited public information, showing early sightings detected on the internet. &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt; and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13086"target="_blank" rel="noopener"&gt;CVE-2025-13086&lt;/a&gt; were the most sighted in this category, each with 6 occurrences.&lt;/p&gt;
&lt;p&gt;In addition, contributor insights covered topics like RCE in Agent DVR, an APT exploiting Cisco and Citrix zero-days discovered by Amazon, and the UNC6148 Backdoors utilizing the OVERSTEP Rootkit on SonicWall SMA 100 Series Devices.&lt;/p&gt;
&lt;h2&gt;Evolution of published CVE in 2025&lt;span class="hx:absolute hx:-mt-20" id="evolution-of-published-cve-in-2025"&gt;&lt;/span&gt;
&lt;a href="#evolution-of-published-cve-in-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/evolution-cve-2025.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/evolution-cve-2025.png" alt="Evolution of published CVE in 2025" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/stats/"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Top 10 Vendors of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/top-10-vendors.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/top-10-vendors.png" alt="Top 10 Vendors of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 Assigners of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-assigners-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-assigners-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/top-10-assigners.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/top-10-assigners.png" alt="Top 10 Assigners of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-64446"target="_blank" rel="noopener"&gt;CVE-2025-64446&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;105&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiWeb"target="_blank" rel="noopener"&gt;FortiWeb&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9084)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;88&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;Server&amp;#43;2019"target="_blank" rel="noopener"&gt;Windows Server 2019&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9565)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21042"target="_blank" rel="noopener"&gt;CVE-2025-21042&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;86&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Samsung Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Mobile&amp;amp;product=Samsung&amp;#43;Mobile&amp;#43;Devices"target="_blank" rel="noopener"&gt;Samsung Mobile Devices&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9308)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58034"target="_blank" rel="noopener"&gt;CVE-2025-58034&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiWeb"target="_blank" rel="noopener"&gt;FortiWeb&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9584)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13223"target="_blank" rel="noopener"&gt;CVE-2025-13223&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9675)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-20198"target="_blank" rel="noopener"&gt;CVE-2023-20198&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;71&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;IOS&amp;#43;XE&amp;#43;Software"target="_blank" rel="noopener"&gt;Cisco IOS XE Software&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9908)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61757"target="_blank" rel="noopener"&gt;CVE-2025-61757&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;67&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation"target="_blank" rel="noopener"&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation&amp;amp;product=Identity&amp;#43;Manager"target="_blank" rel="noopener"&gt;Identity Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9961)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11001"target="_blank" rel="noopener"&gt;CVE-2025-11001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;65&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=7-Zip"target="_blank" rel="noopener"&gt;7-Zip&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=7-Zip&amp;amp;product=7-Zip"target="_blank" rel="noopener"&gt;7-Zip&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9967)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12480"target="_blank" rel="noopener"&gt;CVE-2025-1248&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TrioFox"target="_blank" rel="noopener"&gt;TrioFox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TrioFox&amp;amp;product=TrioFox"target="_blank" rel="noopener"&gt;TrioFox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.4751)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;59&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.744)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Except &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11001"target="_blank" rel="noopener"&gt;CVE-2025-11001&lt;/a&gt;, all listed vulnerabilities are in CISA.&lt;/p&gt;
&lt;h2&gt;Sightings forecast&lt;span class="hx:absolute hx:-mt-20" id="sightings-forecast"&gt;&lt;/span&gt;
&lt;a href="#sightings-forecast" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The following visualizations represent the forecasted number of sightings for various vulnerabilities,
using an adaptive model (decay or logistic growth), with vulnerabilities selected based on having a
sufficient number of sightings and relatively consistent patterns.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2015-2051.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2015-2051.png" alt="Forecast CVE-2015-2051" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2023-20198.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2023-20198.png" alt="Forecast CVE-2023-20198" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2025-59287.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2025-59287.png" alt="Forecast CVE-2025-59287" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2025-64446.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/Forecast-CVE-2025-64446.png" alt="Forecast CVE-2025-64446" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48703"target="_blank" rel="noopener"&gt;CVE-2025-48703&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=centos-webpanel"target="_blank" rel="noopener"&gt;centos-webpanel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=centos-webpanel&amp;amp;product=CentOS&amp;#43;Web&amp;#43;Panel"target="_blank" rel="noopener"&gt;CentOS Web Panel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9836)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11371"target="_blank" rel="noopener"&gt;CVE-2025-11371&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Gladinet"target="_blank" rel="noopener"&gt;Gladinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Gladinet&amp;amp;product=CentreStack&amp;#43;and&amp;#43;TrioFox"target="_blank" rel="noopener"&gt;CentreStack and TrioFox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9575)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21042"target="_blank" rel="noopener"&gt;CVE-2025-21042&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;10/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Samsung Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Mobile&amp;amp;product=Samsung&amp;#43;Mobile&amp;#43;Devices"target="_blank" rel="noopener"&gt;Samsung Mobile Devices&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9308)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9242"target="_blank" rel="noopener"&gt;CVE-2025-9242&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WatchGuard"target="_blank" rel="noopener"&gt;WatchGuard&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=WatchGuard&amp;amp;product=Fireware&amp;#43;OS"target="_blank" rel="noopener"&gt;Fireware OS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9381)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-62215"target="_blank" rel="noopener"&gt;CVE-2025-62215&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9918)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12480"target="_blank" rel="noopener"&gt;CVE-2025-12480&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TrioFox"target="_blank" rel="noopener"&gt;TrioFox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TrioFox&amp;amp;product=TrioFox"target="_blank" rel="noopener"&gt;TrioFox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.4751)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-64446"target="_blank" rel="noopener"&gt;CVE-2025-64446&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiWeb"target="_blank" rel="noopener"&gt;FortiWeb&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9084)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58034"target="_blank" rel="noopener"&gt;CVE-2025-58034&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiWeb"target="_blank" rel="noopener"&gt;FortiWeb&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9584)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13223"target="_blank" rel="noopener"&gt;CVE-2025-13223&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9675)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61757"target="_blank" rel="noopener"&gt;CVE-2025-61757&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;21/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation"target="_blank" rel="noopener"&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation&amp;amp;product=Identity&amp;#43;Manager"target="_blank" rel="noopener"&gt;Identity Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9961)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-26829"target="_blank" rel="noopener"&gt;CVE-2021-26829&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28/11/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=scadabr"target="_blank" rel="noopener"&gt;scadabr&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=scadabr&amp;amp;product=scadabr"target="_blank" rel="noopener"&gt;scadabr&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9951)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;ENISA&lt;span class="hx:absolute hx:-mt-20" id="enisa"&gt;&lt;/span&gt;
&lt;a href="#enisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;No new entry in November.&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2025&amp;amp;month=11"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/top-10-weaknesses.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Click the image for more information.&lt;/p&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;Sightings detected between 2025-11-01 and 2025-11-30 that are associated with vulnerabilities without public records.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Occurrences&lt;/th&gt;
&lt;th&gt;Comment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59396#sightings"target="_blank" rel="noopener"&gt;CVE-2025-59396&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;Not a security vulnerability (&lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0032"target="_blank" rel="noopener"&gt;GCVE&lt;/a&gt; - &lt;a href="https://vulnerability.circl.lu/search?vendor=watchguard"target="_blank" rel="noopener"&gt;watchguard&lt;/a&gt; / &lt;a href="https://vulnerability.circl.lu/search?vendor=watchguard&amp;amp;product=firebox"target="_blank" rel="noopener"&gt;firebox&lt;/a&gt;).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;source: The Shadowserver (honeypot/common-vulnerabilities)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13086#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13086&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;&lt;a href="https://linuxsecurity.com/advisories/ubuntu/ubuntu-7898-1-openvpn-tosysjrrisxy"target="_blank" rel="noopener"&gt;OpenVPN&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-66270#sightings"target="_blank" rel="noopener"&gt;CVE-2025-66270&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;&lt;a href="https://kde.org/info/security/advisory-20251128-1.txt"target="_blank" rel="noopener"&gt;KDE Connect&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11002#sightings"target="_blank" rel="noopener"&gt;CVE-2025-11002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.zerodayinitiative.com/advisories/ZDI-25-950/"target="_blank" rel="noopener"&gt;7-Zip&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9820#sightings"target="_blank" rel="noopener"&gt;CVE-2025-9820&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;&lt;a href="https://seclists.org/oss-sec/2025/q4/203"target="_blank" rel="noopener"&gt;gnutls&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12686#sightings"target="_blank" rel="noopener"&gt;CVE-2025-12686&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.synology.com/en-us/security/advisory/Synology_SA_25_12"target="_blank" rel="noopener"&gt;BeeStation&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-9183#sightings"target="_blank" rel="noopener"&gt;CVE-2024-9183&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/"target="_blank" rel="noopener"&gt;Race condition issue in CI/CD cache impacts GitLab CE/EE&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13167#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13167&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.synology.com/en-global/security/advisory/Synology_SA_25_13"target="_blank" rel="noopener"&gt;Synology&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13392#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13392&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.synology.com/en-br/security/advisory/Synology_SA_25_14"target="_blank" rel="noopener"&gt;Synology&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13593#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13593&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.synology.com/fr-fr/security/advisory/Synology_SA_25_15"target="_blank" rel="noopener"&gt;Synology&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13699#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13699&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.zerodayinitiative.com/advisories/ZDI-25-1025/"target="_blank" rel="noopener"&gt;mariadb-dump Utility&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-23125#sightings"target="_blank" rel="noopener"&gt;CVE-2020-23125&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://bsky.app/profile/beikokucyber.bsky.social/post/3m666laxow323"target="_blank" rel="noopener"&gt;Vulncheck KEV&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-x697-jf34-gp5x#sightings"target="_blank" rel="noopener"&gt;GHSA-x697-jf34-gp5x&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://github.com/wazuh/wazuh/security/advisories/GHSA-x697-jf34-gp5x"target="_blank" rel="noopener"&gt;Wazuh Agent (v4.10.1)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-1045#sightings"target="_blank" rel="noopener"&gt;CVE-2024-1045&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://bsky.app/profile/ferramentaslinux.bsky.social/post/3m65w4mkfek2q"target="_blank" rel="noopener"&gt;GRUB 2&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-36270#sightings"target="_blank" rel="noopener"&gt;CVE-2025-36270&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://portallinuxferramentas.blogspot.com/2025/11/fedora-42-kubernetes-133-security.html"target="_blank" rel="noopener"&gt;Fedora 42 Kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-28840#sightings"target="_blank" rel="noopener"&gt;CVE-2025-28840&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://portallinuxferramentas.blogspot.com/2025/11/securing-your-cluster-deep-dive-into.html"target="_blank" rel="noopener"&gt;Fedora 42 Kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-24481#sightings"target="_blank" rel="noopener"&gt;CVE-2024-24481&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://kb.cert.org/vuls/id/268029"target="_blank" rel="noopener"&gt;Tenda 4G03 Pro and N300 Routers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-59373#sightings"target="_blank" rel="noopener"&gt;CVE-2024-59373&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://infosec.exchange/@cR0w/115610951630509357"target="_blank" rel="noopener"&gt;ASUS&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12345#sightings"target="_blank" rel="noopener"&gt;CVE-2025-12345&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://portallinuxferramentas.blogspot.com/2025/08/critical-sles-security-update.html"target="_blank" rel="noopener"&gt;SUSE Linux Enterprise Server (SLES) security patch&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13207#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13207&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://kb.cert.org/vuls/id/268029"target="_blank" rel="noopener"&gt;Tenda 4G03 Pro and N300 Routers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13698#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13698&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.zerodayinitiative.com/advisories/ZDI-25-1022/"target="_blank" rel="noopener"&gt;Deciso OPNsense&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13700#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13700&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.zerodayinitiative.com/advisories/ZDI-25-1024/"target="_blank" rel="noopener"&gt;DreamFactory saveZipFile&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-13703#sightings"target="_blank" rel="noopener"&gt;CVE-2025-13703&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.zerodayinitiative.com/advisories/ZDI-25-1023/"target="_blank" rel="noopener"&gt;VIPRE Advanced Security&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21140#sightings"target="_blank" rel="noopener"&gt;CVE-2025-21140&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://portallinuxferramentas.blogspot.com/2025/11/critical-keylime-vulnerability-patched.html"target="_blank" rel="noopener"&gt;Oracle Linux 8&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30333#sightings"target="_blank" rel="noopener"&gt;CVE-2025-30333&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://bsky.app/profile/securityrss.bsky.social/post/3m5jnjq7nyr2i"target="_blank" rel="noopener"&gt;Federal civilian agencies are failing to adequately patch vulnerable Cisco devices amid ongoing exploitation&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33514#sightings"target="_blank" rel="noopener"&gt;CVE-2025-33514&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;W3 Total Cache WordPress plugin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33515#sightings"target="_blank" rel="noopener"&gt;CVE-2025-33515&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-44446#sightings"target="_blank" rel="noopener"&gt;CVE-2025-44446&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://isc.sans.edu/diary/Honeypot&amp;#43;FortiWeb&amp;#43;CVE202564446&amp;#43;Exploits/32486"target="_blank" rel="noopener"&gt;Fortiweb&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-52022#sightings"target="_blank" rel="noopener"&gt;CVE-2025-52022&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39"target="_blank" rel="noopener"&gt;emsloyalty backend&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-52023#sightings"target="_blank" rel="noopener"&gt;CVE-2025-52023&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39"target="_blank" rel="noopener"&gt;gemscms backend&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-52024#sightings"target="_blank" rel="noopener"&gt;CVE-2025-52024&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39"target="_blank" rel="noopener"&gt;gemscms POS Platform (backend)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-52025#sightings"target="_blank" rel="noopener"&gt;CVE-2025-52025&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39"target="_blank" rel="noopener"&gt;gemscms backend (POS platform)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-52026#sightings"target="_blank" rel="noopener"&gt;CVE-2025-52026&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39"target="_blank" rel="noopener"&gt;gemscms backend (POS platform)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58388#sightings"target="_blank" rel="noopener"&gt;CVE-2025-58388&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/bundle/cb67ae59-5c4d-4da7-ac88-81db6894b2d8"target="_blank" rel="noopener"&gt;Android: Vulnerability-Lookup bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58390#sightings"target="_blank" rel="noopener"&gt;CVE-2025-58390&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/bundle/cb67ae59-5c4d-4da7-ac88-81db6894b2d8"target="_blank" rel="noopener"&gt;Android: Vulnerability-Lookup bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58392#sightings"target="_blank" rel="noopener"&gt;CVE-2025-58392&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/bundle/cb67ae59-5c4d-4da7-ac88-81db6894b2d8"target="_blank" rel="noopener"&gt;Android: Vulnerability-Lookup bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58394#sightings"target="_blank" rel="noopener"&gt;CVE-2025-58394&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/bundle/cb67ae59-5c4d-4da7-ac88-81db6894b2d8"target="_blank" rel="noopener"&gt;Android: Vulnerability-Lookup bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58396#sightings"target="_blank" rel="noopener"&gt;CVE-2025-58396&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/bundle/cb67ae59-5c4d-4da7-ac88-81db6894b2d8"target="_blank" rel="noopener"&gt;Android: Vulnerability-Lookup bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-58397#sightings"target="_blank" rel="noopener"&gt;CVE-2025-58397&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/bundle/cb67ae59-5c4d-4da7-ac88-81db6894b2d8"target="_blank" rel="noopener"&gt;Android: cVulnerability-Lookup bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-593656#sightings"target="_blank" rel="noopener"&gt;CVE-2025-593656&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://blackhatnews.tokyo/archives/24909"target="_blank" rel="noopener"&gt;ASUS&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-60274#sightings"target="_blank" rel="noopener"&gt;CVE-2025-60274&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://krebsonsecurity.com/2025/11/microsoft-patch-tuesday-november-2025-edition/"target="_blank" rel="noopener"&gt;Windows graphic component (GDI+)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-63721#sightings"target="_blank" rel="noopener"&gt;CVE-2025-63721&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://gist.github.com/k1ng0fic3/e8c8c9353fff8fa95e2c2952587e9266"target="_blank" rel="noopener"&gt;HummerRisk&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-65882#sightings"target="_blank" rel="noopener"&gt;CVE-2025-65882&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://gist.github.com/AradCohen/939ee50d60c4d2bd555a364615a5ab9c"target="_blank" rel="noopener"&gt;OpenMPTCProuter&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/c4273ed6-7073-4456-bb8f-28d2b213259b"target="_blank" rel="noopener"&gt;RCE in Agent DVR&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/3b6bbd4e-9be5-48b3-8a2d-10b2b5f5da17"target="_blank" rel="noopener"&gt;Amazon discovers APT exploiting Cisco and Citrix zero-days&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/647bd131-5525-47ea-8d98-53d132cabe2e"target="_blank" rel="noopener"&gt;Suricata 8.0.2 and 7.0.13 released - including multiple vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/3d3050ec-b24b-4cf2-b07d-6fa859b0f201"target="_blank" rel="noopener"&gt;UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>End-of-Year Threat Intelligence Sightings Forecast</title><link>http://www.vulnerability-lookup.org/2025/12/02/end-of-year-threat-intelligence-sightings-forecast/</link><pubDate>Tue, 02 Dec 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/12/02/end-of-year-threat-intelligence-sightings-forecast/</guid><description>
&lt;h2&gt;Introduction and Methodology&lt;span class="hx:absolute hx:-mt-20" id="introduction-and-methodology"&gt;&lt;/span&gt;
&lt;a href="#introduction-and-methodology" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This report presents an analysis of &lt;strong&gt;Threat Intelligence (TI) Sightings&lt;/strong&gt; aggregated from several key data sources, including social platforms, code repositories, and specialized TI feeds.
The primary objective is to visually track historical trends per source and provide a short-term &lt;strong&gt;adaptive forecast&lt;/strong&gt; for a defined period (in days).&lt;/p&gt;
&lt;p&gt;For the global view (aggregating all sighting types), we applied a &lt;strong&gt;SARIMAX&lt;/strong&gt; model and compared it with an &lt;strong&gt;Adaptive / Exponential Decay&lt;/strong&gt; approach to highlight differing trend interpretations.&lt;/p&gt;
&lt;p&gt;The data pipeline and analysis for source-specific sightings follow two main steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Historical Trend (Weekly)&lt;/strong&gt;: Sightings are filtered by source, aggregated weekly by domain within that source (e.g., individual Fediverse instances), and visualized to show distribution and activity patterns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Adaptive Forecast (Daily)&lt;/strong&gt;: Total daily sightings per source are analyzed to determine the &lt;strong&gt;underlying trend&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Increasing trend&lt;/strong&gt; → fitted with a &lt;strong&gt;Logistic Growth&lt;/strong&gt; model to project potential saturation points.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Decreasing trend&lt;/strong&gt; → fitted with an &lt;strong&gt;Exponential Decay&lt;/strong&gt; model to estimate a future baseline or floor.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The next sections display &lt;strong&gt;historical charts&lt;/strong&gt; (weekly aggregation by sub-domain) and &lt;strong&gt;predictive charts&lt;/strong&gt; (daily total counts) for each analyzed source.&lt;/p&gt;
&lt;p&gt;Data is available &lt;a href="https://vulnerability.circl.lu/dumps/sightings.ndjson"target="_blank" rel="noopener"&gt;here&lt;/a&gt;,
and the report is also available as a &lt;a href="http://www.vulnerability-lookup.org/files/news/2025/12/End-of-Year-Threat-Intelligence-Sightings-Forecast.pdf"&gt;PDF&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h3&gt;Adaptive Forecast&lt;span class="hx:absolute hx:-mt-20" id="adaptive-forecast"&gt;&lt;/span&gt;
&lt;a href="#adaptive-forecast" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;To predict the number of sightings over time, we adaptively select the forecasting model based on the observed trend slope.
This is achieved independently for each pipeline.&lt;/p&gt;
&lt;p&gt;Exponential Decay model:&lt;/p&gt;
&lt;span class="katex-display"&gt;&lt;span class="katex"&gt;&lt;span class="katex-mathml"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML" display="block"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mo&gt;⋅&lt;/mo&gt;&lt;msup&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mrow&gt;&lt;mo&gt;−&lt;/mo&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;/mrow&gt;&lt;/msup&gt;&lt;mo&gt;+&lt;/mo&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
y(t) = a \cdot e^{-bt} + c
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;span class="katex-html" aria-hidden="true"&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:1em;vertical-align:-0.25em;"&gt;&lt;/span&gt;&lt;span class="mord mathnormal" style="margin-right:0.03588em;"&gt;y&lt;/span&gt;&lt;span class="mopen"&gt;(&lt;/span&gt;&lt;span class="mord mathnormal"&gt;t&lt;/span&gt;&lt;span class="mclose"&gt;)&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;span class="mrel"&gt;=&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:0.4445em;"&gt;&lt;/span&gt;&lt;span class="mord mathnormal"&gt;a&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;span class="mbin"&gt;⋅&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:0.9824em;vertical-align:-0.0833em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mord mathnormal"&gt;e&lt;/span&gt;&lt;span class="msupsub"&gt;&lt;span class="vlist-t"&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:0.8991em;"&gt;&lt;span style="top:-3.113em;margin-right:0.05em;"&gt;&lt;span class="pstrut" style="height:2.7em;"&gt;&lt;/span&gt;&lt;span class="sizing reset-size6 size3 mtight"&gt;&lt;span class="mord mtight"&gt;&lt;span class="mord mtight"&gt;−&lt;/span&gt;&lt;span class="mord mathnormal mtight"&gt;b&lt;/span&gt;&lt;span class="mord mathnormal mtight"&gt;t&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;span class="mbin"&gt;+&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:0.4306em;"&gt;&lt;/span&gt;&lt;span class="mord mathnormal"&gt;c&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;p&gt;Logistic Growth model:&lt;/p&gt;
&lt;span class="katex-display"&gt;&lt;span class="katex"&gt;&lt;span class="katex-mathml"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML" display="block"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mfrac&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mrow&gt;&lt;mn&gt;1&lt;/mn&gt;&lt;mo&gt;+&lt;/mo&gt;&lt;msup&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mrow&gt;&lt;mo&gt;−&lt;/mo&gt;&lt;mi&gt;k&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mo&gt;−&lt;/mo&gt;&lt;msub&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;/msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;/msup&gt;&lt;/mrow&gt;&lt;/mfrac&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
y(t) = \frac{L}{1 + e^{-k(t-t_0)}}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;span class="katex-html" aria-hidden="true"&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:1em;vertical-align:-0.25em;"&gt;&lt;/span&gt;&lt;span class="mord mathnormal" style="margin-right:0.03588em;"&gt;y&lt;/span&gt;&lt;span class="mopen"&gt;(&lt;/span&gt;&lt;span class="mord mathnormal"&gt;t&lt;/span&gt;&lt;span class="mclose"&gt;)&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;span class="mrel"&gt;=&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2778em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="base"&gt;&lt;span class="strut" style="height:2.1477em;vertical-align:-0.7873em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mopen nulldelimiter"&gt;&lt;/span&gt;&lt;span class="mfrac"&gt;&lt;span class="vlist-t vlist-t2"&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:1.3603em;"&gt;&lt;span style="top:-2.296em;"&gt;&lt;span class="pstrut" style="height:3em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mord"&gt;1&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;span class="mbin"&gt;+&lt;/span&gt;&lt;span class="mspace" style="margin-right:0.2222em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mord mathnormal"&gt;e&lt;/span&gt;&lt;span class="msupsub"&gt;&lt;span class="vlist-t"&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:0.814em;"&gt;&lt;span style="top:-2.989em;margin-right:0.05em;"&gt;&lt;span class="pstrut" style="height:2.7em;"&gt;&lt;/span&gt;&lt;span class="sizing reset-size6 size3 mtight"&gt;&lt;span class="mord mtight"&gt;&lt;span class="mord mtight"&gt;−&lt;/span&gt;&lt;span class="mord mathnormal mtight" style="margin-right:0.03148em;"&gt;k&lt;/span&gt;&lt;span class="mopen mtight"&gt;(&lt;/span&gt;&lt;span class="mord mathnormal mtight"&gt;t&lt;/span&gt;&lt;span class="mbin mtight"&gt;−&lt;/span&gt;&lt;span class="mord mtight"&gt;&lt;span class="mord mathnormal mtight"&gt;t&lt;/span&gt;&lt;span class="msupsub"&gt;&lt;span class="vlist-t vlist-t2"&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:0.3173em;"&gt;&lt;span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"&gt;&lt;span class="pstrut" style="height:2.5em;"&gt;&lt;/span&gt;&lt;span class="sizing reset-size3 size1 mtight"&gt;&lt;span class="mord mtight"&gt;0&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="vlist-s"&gt;​&lt;/span&gt;&lt;/span&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:0.143em;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="mclose mtight"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="top:-3.23em;"&gt;&lt;span class="pstrut" style="height:3em;"&gt;&lt;/span&gt;&lt;span class="frac-line" style="border-bottom-width:0.04em;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="top:-3.677em;"&gt;&lt;span class="pstrut" style="height:3em;"&gt;&lt;/span&gt;&lt;span class="mord"&gt;&lt;span class="mord mathnormal"&gt;L&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="vlist-s"&gt;​&lt;/span&gt;&lt;/span&gt;&lt;span class="vlist-r"&gt;&lt;span class="vlist" style="height:0.7873em;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="mclose nulldelimiter"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;p&gt;The implementation is available on &lt;a href="https://github.com/vulnerability-lookup/TARDISsight"target="_blank" rel="noopener"&gt;GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Global View&lt;span class="hx:absolute hx:-mt-20" id="global-view"&gt;&lt;/span&gt;
&lt;a href="#global-view" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-global-sarimax.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-global-sarimax.png" alt="SARIMAX Forecast" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We have aggregated over 165,000 sightings since 1999-01-01; however, for the global view, we focus on the past year of data.
Notably, collection volumes have grown significantly since September 2024, driven by the deployment of our
&lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/#automation-tools"target="_blank" rel="noopener"&gt;various sighting tools&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-global-decay.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-global-decay.png" alt="Decay model" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Insights:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The SARIMAX model captures cyclical patterns in sightings and can detect emerging surges.&lt;/li&gt;
&lt;li&gt;The decay model emphasizes a long-term baseline, highlighting periods when activity naturally declines.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;Fediverse&lt;span class="hx:absolute hx:-mt-20" id="fediverse"&gt;&lt;/span&gt;
&lt;a href="#fediverse" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The Fediverse is a network of decentralized social servers (e.g., Mastodon instances). Monitoring sightings here provides early signals of community-driven threat reporting.&lt;/p&gt;
&lt;h3&gt;Historical Activity (Weekly)&lt;span class="hx:absolute hx:-mt-20" id="historical-activity-weekly"&gt;&lt;/span&gt;
&lt;a href="#historical-activity-weekly" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-fediverse.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-fediverse.png" alt="Historical data" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Observations:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Peaks appear to correspond to bursts of discussion, often triggered by the vendor involved in a vulnerability or by its severity and exploitability.&lt;/li&gt;
&lt;li&gt;Activity varies across instances, indicating heterogeneous engagement in TI reporting.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Adaptive Forecast (Daily)&lt;span class="hx:absolute hx:-mt-20" id="adaptive-forecast-daily"&gt;&lt;/span&gt;
&lt;a href="#adaptive-forecast-daily" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-fediverse.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-fediverse.png" alt="Forecast" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Insights:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The forecast suggests a &lt;strong&gt;decreasing trend&lt;/strong&gt;, approaching a floor near &lt;strong&gt;17 sightings/day&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Analysts can interpret this as a stabilization phase after recent high-activity events.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;Bluesky&lt;span class="hx:absolute hx:-mt-20" id="bluesky"&gt;&lt;/span&gt;
&lt;a href="#bluesky" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Bluesky serves as a decentralized, modern social platform for security discussions, similar to the Fediverse.&lt;/p&gt;
&lt;h3&gt;Historical Activity (Weekly)&lt;span class="hx:absolute hx:-mt-20" id="historical-activity-weekly-1"&gt;&lt;/span&gt;
&lt;a href="#historical-activity-weekly-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-bluesky.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-bluesky.png" alt="Historical data" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Observations:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Weekly fluctuations mirror platform engagement cycles, including release-driven spikes in TI information.&lt;/li&gt;
&lt;li&gt;Consistent reporting from Bluesky suggests it is an increasingly relevant source for threat detection.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Adaptive Forecast (Daily)&lt;span class="hx:absolute hx:-mt-20" id="adaptive-forecast-daily-1"&gt;&lt;/span&gt;
&lt;a href="#adaptive-forecast-daily-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-bluesky.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-bluesky.png" alt="Forecast" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Insights:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Slightly decreasing trend with a projected floor around &lt;strong&gt;146 sightings/day&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Sustained engagement indicates Bluesky remains a reliable source for early TI signals.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;Gist&lt;span class="hx:absolute hx:-mt-20" id="gist"&gt;&lt;/span&gt;
&lt;a href="#gist" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Gist is a critical source for sharing code, configuration files, PoCs, and raw threat data.&lt;/p&gt;
&lt;h3&gt;Historical Activity (Weekly)&lt;span class="hx:absolute hx:-mt-20" id="historical-activity-weekly-2"&gt;&lt;/span&gt;
&lt;a href="#historical-activity-weekly-2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-gist.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-gist.png" alt="Historical data" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Observations:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Sharp weekly spikes often coincide with the release of new PoCs, significant configuration dumps, or data leaks.&lt;/li&gt;
&lt;li&gt;Activity intensity correlates with major vulnerability announcements. Sometimes even before the availability of the CVE record.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Adaptive Forecast (Daily)&lt;span class="hx:absolute hx:-mt-20" id="adaptive-forecast-daily-2"&gt;&lt;/span&gt;
&lt;a href="#adaptive-forecast-daily-2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-gist.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-gist.png" alt="Forecast" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Insights:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Forecast indicates a &lt;strong&gt;slightly rising trend&lt;/strong&gt;, stabilizing around &lt;strong&gt;32 sightings/day&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Analysts can interpret this as a steady flow of early-stage threat artifacts.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;MISP&lt;span class="hx:absolute hx:-mt-20" id="misp"&gt;&lt;/span&gt;
&lt;a href="#misp" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;MISP provides curated, high-confidence threat intelligence sightings.
Although the volume of vulnerability-related observations is lower than that of social platforms, the data is more structured and consistently reliable, offering higher-quality intelligence.
This is partly because the MISP dedicated sighting tool explicitly targets attributes associated with the specific vulnerability type.
The sporadic nature of these sightings makes mid-term forecasting challenging, even when using adaptive methods such as SARIMAX.
As such, the results should be treated with caution. We plan to improve our MISP sighting tool to identify vulnerability sightings in objects not labeled as vulnerabilities.&lt;/p&gt;
&lt;h3&gt;Historical Activity (Weekly)&lt;span class="hx:absolute hx:-mt-20" id="historical-activity-weekly-3"&gt;&lt;/span&gt;
&lt;a href="#historical-activity-weekly-3" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-misp.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-misp.png" alt="Historical data" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Observations:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Weekly activity is smoother, reflecting institutional contributions and structured updates.&lt;/li&gt;
&lt;li&gt;Bursts in activity typically coincide with major vulnerability events, as multiple contributors
across the MISP network submit sightings, highlighting coordinated focus on high-impact disclosures.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Adaptive Forecast (Daily)&lt;span class="hx:absolute hx:-mt-20" id="adaptive-forecast-daily-3"&gt;&lt;/span&gt;
&lt;a href="#adaptive-forecast-daily-3" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-misp.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-misp.png" alt="Forecast" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Insights:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Logistic growth model&lt;/strong&gt; suggests rising activity, with daily sightings expected to peak near &lt;strong&gt;96/day&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Indicates increased structured intelligence input, beneficial for high-confidence threat detection.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;The Shadowserver Foundation&lt;span class="hx:absolute hx:-mt-20" id="the-shadowserver-foundation"&gt;&lt;/span&gt;
&lt;a href="#the-shadowserver-foundation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The Shadowserver Foundation is a cornerstone resource for security researchers, providing an extensive wealth of
data on real-world exploits and their associated vulnerabilities, complete with daily statistics and geographical insights.&lt;/p&gt;
&lt;h3&gt;Historical Activity (Weekly)&lt;span class="hx:absolute hx:-mt-20" id="historical-activity-weekly-4"&gt;&lt;/span&gt;
&lt;a href="#historical-activity-weekly-4" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-shadowserver.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-shadowserver.png" alt="Historical data" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Our daily sightings from the Shadowserver Foundation are based on the &lt;a href="https://github.com/The-Shadowserver-Foundation/api_utils/wiki/API:-Honeypot"target="_blank" rel="noopener"&gt;honeypot group&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Exploited vulnerabilities (type: exploited):
&lt;a href="https://vulnerability.circl.lu/sightings/?query=honeypot%2Fexploited-vulnerabilities"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/sightings/?query=honeypot%2Fexploited-vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Common vulnerabilities (type: seen):
&lt;a href="https://vulnerability.circl.lu/sightings/?query=honeypot%2Fcommon-vulnerabilities"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/sightings/?query=honeypot%2Fcommon-vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Adaptive Forecast (Daily)&lt;span class="hx:absolute hx:-mt-20" id="adaptive-forecast-daily-4"&gt;&lt;/span&gt;
&lt;a href="#adaptive-forecast-daily-4" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-shadowserver.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-shadowserver.png" alt="Forecast" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The volume of observations is expected to show slight growth, peaking at approximately &lt;strong&gt;128/day&lt;/strong&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Metasploit&lt;span class="hx:absolute hx:-mt-20" id="metasploit"&gt;&lt;/span&gt;
&lt;a href="#metasploit" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Metasploit sightings typically reflect tool-based testing or exploitation activity.&lt;/p&gt;
&lt;h3&gt;Historical Activity (Weekly)&lt;span class="hx:absolute hx:-mt-20" id="historical-activity-weekly-5"&gt;&lt;/span&gt;
&lt;a href="#historical-activity-weekly-5" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-metasploit.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-metasploit.png" alt="Historical data" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Observations:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Peaks align with active exploitation campaigns or &lt;strong&gt;module releases&lt;/strong&gt;, which is a good indicator of exploitability.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Adaptive Forecast (Daily)&lt;span class="hx:absolute hx:-mt-20" id="adaptive-forecast-daily-5"&gt;&lt;/span&gt;
&lt;a href="#adaptive-forecast-daily-5" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-metasploit.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/12/sightings-forecast-metasploit.png" alt="Forecast" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Exponential decay forecast with a floor approximately to &lt;strong&gt;2/day&lt;/strong&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Conclusion&lt;span class="hx:absolute hx:-mt-20" id="conclusion"&gt;&lt;/span&gt;
&lt;a href="#conclusion" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Social sources (Fediverse, Bluesky) display &lt;strong&gt;volatile, event-driven patterns&lt;/strong&gt;, reflecting community discussions.&lt;/li&gt;
&lt;li&gt;Structured sources (MISP, Shadow Server, Gist) exhibit &lt;strong&gt;smoother, more predictable trends&lt;/strong&gt;, providing higher-confidence intelligence.&lt;/li&gt;
&lt;li&gt;Forecasting models support &lt;strong&gt;short-term planning&lt;/strong&gt;, allowing teams to anticipate surges (Logistic Growth) or declines (Exponential Decay) in incoming TI sightings.&lt;/li&gt;
&lt;li&gt;Combining multiple sources ensures a &lt;strong&gt;balanced situational awareness&lt;/strong&gt;, capturing both early signals and verified intelligence.&lt;/li&gt;
&lt;li&gt;A potential path forward involves &lt;strong&gt;attributing weights to sightings&lt;/strong&gt; according to their origin.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Key Takeaways:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Early detection: Social platforms provide rapid but noisy signals.&lt;/li&gt;
&lt;li&gt;Reliability: Structured sources confirm and validate threats.&lt;/li&gt;
&lt;li&gt;Adaptive planning: Forecasting helps resource allocation for analysts and SOCs.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) aims to enhance Cyber Threat Intelligence (CTI) products across the EU, supporting coordinated reporting and reducing redundancy among SOCs and CSIRTs.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) contributes extensive expertise in incident management, threat intelligence, and open-source cybersecurity tools, playing a pivotal role in fostering &lt;strong&gt;cross-European collaboration&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.18.0 released</title><link>http://www.vulnerability-lookup.org/2025/11/14/vulnerability-lookup-2-18-0/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/11/14/vulnerability-lookup-2-18-0/</guid><description>
&lt;p&gt;We’re delighted to announce the release of &lt;strong&gt;Vulnerability-Lookup 2.18.0&lt;/strong&gt; — packed with exciting new features!&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h4&gt;Integration with Rulezet&lt;span class="hx:absolute hx:-mt-20" id="integration-with-rulezet"&gt;&lt;/span&gt;
&lt;a href="#integration-with-rulezet" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;&lt;a href="https://github.com/ngsoti/rulezet-core"target="_blank" rel="noopener"&gt;Rulezet&lt;/a&gt; is an open-source platform for sharing, evaluating, improving, and managing &lt;strong&gt;cybersecurity detection rules&lt;/strong&gt; (YARA, Sigma, Suricata, etc.).
Its goal is to foster collaboration among professionals and enthusiasts to enhance the quality and reliability of detection rules.&lt;/p&gt;
&lt;p&gt;Vulnerability-Lookup can now be configured to interface with the API of any Rulezet instance, providing insights into existing detection rules related to security vulnerabilities.&lt;br&gt;
The default Rulezet instance enabled in Vulnerability-Lookup is hosted at &lt;a href="https://rulezet.org"target="_blank" rel="noopener"&gt;https://rulezet.org&lt;/a&gt; and currently offers more than 122,000 security rules.&lt;/p&gt;
&lt;p&gt;Detection rules related to vulnerabilities are displayed on the vulnerability details page (in a dedicated tab) and on bundle details pages.&lt;/p&gt;
&lt;p&gt;Implemented in &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/280"target="_blank" rel="noopener"&gt;#280&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/rulezet-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/rulezet-1.png" alt="Detection rules related to a vulnerability" loading="lazy" /&gt;&lt;/a&gt;
&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-26134#detection-rules"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/CVE-2022-26134#detection-rules&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/rulezet-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/rulezet-2.png" alt="Detection rules related to a bundle" loading="lazy" /&gt;&lt;/a&gt;
&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2014-6271#detection-rules"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/CVE-2014-6271#detection-rules&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You can even query the remote Rulezet instance via the Vulnerability-Lookup API:&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/rulezet/search_rules_by_vulnerabilities/CVE-2020-27130?page=1&amp;amp;per_page=50&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;metadata&amp;#34;&lt;/span&gt;: &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;: 3,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;page&amp;#34;&lt;/span&gt;: 1,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;per_page&amp;#34;&lt;/span&gt;: &lt;span class="m"&gt;50&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;data&amp;#34;&lt;/span&gt;: &lt;span class="o"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;id&amp;#34;&lt;/span&gt;: 122599,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;84846673-015e-450b-8a73-2ba481b5a6ce&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability_id&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;CVE-2020-27130&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;format&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;suricata&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;title&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Exploit CVE-2020-27130 on Cisco Security Manager - Upload webshell&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Rule for security (detection rule in many format)&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;raw&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;alert http any any -&amp;gt; any any (msg:\&amp;#34;Exploit CVE-2020-27130 on Cisco Security Manager - Upload webshell\&amp;#34;; flow:to_server,established; content:\&amp;#34;POST\&amp;#34;; http_method; content:\&amp;#34;/cwhp/XmpFileUploadServlet\&amp;#34;; startswith; http_uri; pcre:\&amp;#34;/filename=\\\&amp;#34;.*\\.\\.\\/.+\\\&amp;#34;\\r\\n/P\&amp;#34;; reference:cve,CVE-2020-27130; classtype:web-application-attack; sid:2020271303; rev:1;)&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;detail_url&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;https://rulezet.org/rule/detail_rule/122599&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;creation_date&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;2025-11-06 13:03&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;updated_date&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;2025-11-13 09:33&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;id&amp;#34;&lt;/span&gt;: 122598,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;538dafc1-d49c-4fd6-bdb5-57b997346fe6&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability_id&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;CVE-2020-27130&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;format&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;suricata&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;title&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Exploit CVE-2020-27130 on Cisco Security Manager - Download arbitrary directory as a zip file&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Rule for security (detection rule in many format)&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;raw&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;alert http any any -&amp;gt; any any (msg:\&amp;#34;Exploit CVE-2020-27130 on Cisco Security Manager - Download arbitrary directory as a zip file\&amp;#34;; flow:to_server,established; content:\&amp;#34;GET\&amp;#34;; http_method; pcre:\&amp;#34;/^\\/cwhp\\/(Xmp|Sample)FileDownloadServlet/U\&amp;#34;; content:\&amp;#34;../\&amp;#34;; distance:0; http_uri; reference:cve,CVE-2020-27130; classtype:web-application-attack; sid:2020271302; rev:1;)&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;detail_url&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;https://rulezet.org/rule/detail_rule/122598&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;creation_date&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;2025-11-06 13:03&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;updated_date&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;2025-11-06 13:03&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;id&amp;#34;&lt;/span&gt;: 122597,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;2cd8fb2a-e97b-4390-8dca-d416b2858c66&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability_id&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;CVE-2020-27130&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;format&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;suricata&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;title&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Exploit CVE-2020-27130 on Cisco Security Manager - Download arbitrary file&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Rule for security (detection rule in many format)&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;raw&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;alert http any any -&amp;gt; any any (msg:\&amp;#34;Exploit CVE-2020-27130 on Cisco Security Manager - Download arbitrary file\&amp;#34;; flow:to_server,established; content:\&amp;#34;GET\&amp;#34;; http_method; pcre:\&amp;#34;/^\\/athena\\/(xdmProxy\\/(xdmConfig|xdmResources)|itf\\/resultsFrame\\.jsp)/U\&amp;#34;; content:\&amp;#34;../\&amp;#34;; distance:0; http_uri; reference:cve,CVE-2020-27130; classtype:web-application-attack; sid:2020271301; rev:1;)&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;detail_url&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;https://rulezet.org/rule/detail_rule/122597&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;creation_date&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;2025-11-06 13:03&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;updated_date&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;2025-11-06 13:03&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Thanks to &lt;a href="https://github.com/ecrou-exact"target="_blank" rel="noopener"&gt;Théo Geffe&lt;/a&gt; for making this integration possible.&lt;/p&gt;
&lt;h4&gt;Indexing Information Related to Assigners (CNA)&lt;span class="hx:absolute hx:-mt-20" id="indexing-information-related-to-assigners-cna"&gt;&lt;/span&gt;
&lt;a href="#indexing-information-related-to-assigners-cna" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Information about security advisory assigners is now indexed. CNAs from the official CVE Program source (cvelistv5) are indexed in Kvrocks, with GNAs planned for the future.&lt;br&gt;
The API exposes this data via a new &lt;strong&gt;assigners&lt;/strong&gt; endpoint. From an API perspective, both CNAs and GNAs are treated as assigners, though they will be stored in dedicated indexes.&lt;/p&gt;
&lt;p&gt;Updates include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enhanced search capabilities related to assigners.&lt;/li&gt;
&lt;li&gt;Improved &lt;a href="https://vulnerability.circl.lu/stats/"target="_blank" rel="noopener"&gt;/stats&lt;/a&gt; page.&lt;/li&gt;
&lt;li&gt;Updated vulnerability details page: display the assigner name with a link.&lt;/li&gt;
&lt;li&gt;A &lt;a href="https://vulnerability.circl.lu/assigners/"target="_blank" rel="noopener"&gt;new page listing assigners&lt;/a&gt;, similar to the existing CWE list.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Implemented in &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/283"target="_blank" rel="noopener"&gt;PR #283&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/search-with-assigner.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/search-with-assigner.png" alt="Search with assigners filter" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/stats-page.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/stats-page.png" alt="Top assigners charts" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h4&gt;Website&lt;span class="hx:absolute hx:-mt-20" id="website"&gt;&lt;/span&gt;
&lt;a href="#website" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;new: [website] Add PROTECT_USER_PAGES option to restrict user profile pages to authenticated users.
Closes (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/277"target="_blank" rel="noopener"&gt;#277&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Vulnerability Sources&lt;span class="hx:absolute hx:-mt-20" id="vulnerability-sources"&gt;&lt;/span&gt;
&lt;a href="#vulnerability-sources" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Added &lt;a href="https://vulnerability.circl.lu/recent#csaf_abb"target="_blank" rel="noopener"&gt;ABB CSAF feed&lt;/a&gt;
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0d984a82771348adb70140b578541a9564f71d4c"target="_blank" rel="noopener"&gt;0d984a8&lt;/a&gt;) by &lt;a href="https://github.com//neutrinoguy"target="_blank" rel="noopener"&gt;@neutrinoguy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;It now possible to enable a list of enabled feeders via the config/modules.cfg file.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e4a1acbff8fd5b40f972e982dc22cbc8f8b861a4"target="_blank" rel="noopener"&gt;e4a1acb&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="hx:overflow-x-auto hx:mt-6 hx:flex hx:rounded-lg hx:border hx:py-2 hx:ltr:pr-4 hx:rtl:pl-4 hx:contrast-more:border-current hx:contrast-more:dark:border-current hx:border-blue-200 hx:bg-blue-100 hx:text-blue-900 hx:dark:border-blue-200/30 hx:dark:bg-blue-900/30 hx:dark:text-blue-200"&gt;
&lt;div class="hx:ltr:pl-3 hx:ltr:pr-2 hx:rtl:pr-3 hx:rtl:pl-2"&gt;&lt;svg height=1.2em class="hx:inline-block hx:align-middle" xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M13 16h-1v-4h-1m1-4h.01M21 12a9 9 0 11-18 0 9 9 0 0118 0z"/&gt;&lt;/svg&gt;&lt;/div&gt;
&lt;div class="hx:w-full hx:min-w-0 hx:leading-7"&gt;
&lt;div class="hx:mt-6 hx:leading-7 hx:first:mt-0"&gt;After updating, run the script: &lt;code&gt;bin/index_vulnerabilities.py&lt;/code&gt;. This will index the CNAs and update the Kvrocks indexes. The process takes approximately 15 minutes.
Next, run: &lt;code&gt;bin/index_cwe.py&lt;/code&gt;. This will complete in under 2 minutes.&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hx:overflow-x-auto hx:mt-6 hx:flex hx:rounded-lg hx:border hx:py-2 hx:ltr:pr-4 hx:rtl:pl-4 hx:contrast-more:border-current hx:contrast-more:dark:border-current hx:border-blue-200 hx:bg-blue-100 hx:text-blue-900 hx:dark:border-blue-200/30 hx:dark:bg-blue-900/30 hx:dark:text-blue-200"&gt;
&lt;div class="hx:ltr:pl-3 hx:ltr:pr-2 hx:rtl:pr-3 hx:rtl:pl-2"&gt;&lt;svg height=1.2em class="hx:inline-block hx:align-middle" xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M13 16h-1v-4h-1m1-4h.01M21 12a9 9 0 11-18 0 9 9 0 0118 0z"/&gt;&lt;/svg&gt;&lt;/div&gt;
&lt;div class="hx:w-full hx:min-w-0 hx:leading-7"&gt;
&lt;div class="hx:mt-6 hx:leading-7 hx:first:mt-0"&gt;Please make sure your feeders configuration file (&lt;code&gt;config/modules.cfg&lt;/code&gt;) is up to date. See the &lt;a href="https://www.vulnerability-lookup.org/documentation/installation.html#modules"target="_blank" rel="noopener"&gt;documentation&lt;/a&gt;.&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;chg: [website] Account creation via the API is now rate-limited to 3 registrations per hour per IP.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3a12de293039bef5f77c33b1e61f843a698c60be"target="_blank" rel="noopener"&gt;3a12de2&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Additional validation checks have been added to reject email addresses that are disposable (MISP list), from blocked domains, or with invalid MX records.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3a12de293039bef5f77c33b1e61f843a698c60be"target="_blank" rel="noopener"&gt;3a12de2&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;chg: [website] Improved email address check in both the API endpoint and in the form controller.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/bb090fcd64011bd99354d15f4008feff20dbf126"target="_blank" rel="noopener"&gt;bb090fc&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;chg: [website] user.last_seen is now updated after successful login.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/fb5796e774aaada70cc65ab775b0884d066abf5b"target="_blank" rel="noopener"&gt;fb5796e&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;chg: [API] Improved date parsing for sightings
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d7bc9fde169f9d2c17ded8f35cd103dd32be6dcc"target="_blank" rel="noopener"&gt;d7bc9fd&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;chg: [website] Harmonization of the templates for the details views of bundles and comments.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/c7f90aa4b1fad866e941e6c2cf78b419544b38bb"target="_blank" rel="noopener"&gt;c7f90aa&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;chg: [feeders] Improved use of the kvrocks counters for vendors and cwe rankings.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/120567051da0e68bdec449ef3b908859d6a16967"target="_blank" rel="noopener"&gt;1205670&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;chg: [notifications] add random jitter to reschedule execution times
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/d974315229678aff3880e264f966bd68ff5b6651"target="_blank" rel="noopener"&gt;d974315&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;various minor improvements to the backend, user interface and documentation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Refreshed views&lt;span class="hx:absolute hx:-mt-20" id="refreshed-views"&gt;&lt;/span&gt;
&lt;a href="#refreshed-views" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/search.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/search.png" alt="Search page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/comment.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/comment.png" alt="Comment details" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/list-comments.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/list-comments.png" alt="List of comments with filtering" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/list-bundles.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/list-bundles.png" alt="List of bundles" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;fix: [website] Redirect the user to the user_bp.watchlist view if notifications are found.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/4f6e0bcdeab737f668ef9b0898330f6240128c6d"target="_blank" rel="noopener"&gt;4f6e0bc&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;fix: [API] Delete notifications of the user to delete.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/23719629c8507f13ee5c5b35c08bc39d707e8373"target="_blank" rel="noopener"&gt;2371962&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Rename flatpickr to flatpickr.js and update template reference
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/8dcc8049c3a842563c92a869d21a9eb449db06b1"target="_blank" rel="noopener"&gt;8dcc804&lt;/a&gt;) by &lt;a href="https://github.com/DocArmoryTech"target="_blank" rel="noopener"&gt;@DocArmoryTech&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.18.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.18.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
We appreciate your feedback!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Advancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platform at Unlock Your Bain conference</title><link>http://www.vulnerability-lookup.org/2025/11/08/unlock-your-brain-2025/</link><pubDate>Sat, 08 Nov 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/11/08/unlock-your-brain-2025/</guid><description>
&lt;h2&gt;Slides: &lt;strong&gt;Advancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platform&lt;/strong&gt;&lt;span class="hx:absolute hx:-mt-20" id="slides-advancing-vulnerability-tracking-and-disclosure-through-an-open-and-distributed-platform"&gt;&lt;/span&gt;
&lt;a href="#slides-advancing-vulnerability-tracking-and-disclosure-through-an-open-and-distributed-platform" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;We presented &lt;strong&gt;“Advancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platform”&lt;/strong&gt; at the excellent &lt;a href="https://unlockyourbrain.bzh/"target="_blank" rel="noopener"&gt;Unlock Your Brain conference&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A well-organised and welcoming event, Unlock Your Brain brings together a great mix of researchers, practitioners, and open-source enthusiasts—making it a perfect place to exchange ideas on vulnerability tracking and disclosure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Download the slides:&lt;/strong&gt;&lt;br&gt;
&lt;a href="http://www.vulnerability-lookup.org/files/events/2025/presentation-unlockyourbrain.pdf"&gt;https://www.vulnerability-lookup.org/files/events/2025/presentation-unlockyourbrain.pdf&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - October 2025</title><link>http://www.vulnerability-lookup.org/2025/11/04/vulnerability-report-october-2025/</link><pubDate>Tue, 04 Nov 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/11/04/vulnerability-report-october-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for October 2025, based on sightings collected from various sources,
including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, Metasploit, and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The October 2025 cybersecurity landscape has seen significant activity, with several high-profile vulnerabilities garnering attention due to widespread sightings and critical severity ratings. Analysis of the top 10 vulnerabilities of the month highlights major exposures across enterprise software, server platforms, and popular development tools.&lt;/p&gt;
&lt;p&gt;At the forefront is &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61882"target="_blank" rel="noopener"&gt;CVE-2025-61882&lt;/a&gt;, affecting Oracle Concurrent Processing, which accumulated 241 sightings and is classified as critical with a &lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI&lt;/a&gt; confidence score of 0.9963. Close behind is &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;, impacting Microsoft Windows Server 2019, with 235 sightings and critical severity (confidence 0.9565). Redis also experienced notable issues with CVE-2025-49844, recording 106 sightings and critical classification, while Unity3D&amp;rsquo;s Unity Editor (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59489"target="_blank" rel="noopener"&gt;CVE-2025-59489&lt;/a&gt;) and Oracle Configurator (CVE-2025-61884) were flagged as high-risk vulnerabilities with 98 and 95 sightings, respectively. Adobe Commerce&amp;rsquo;s &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt; further highlights the ongoing risk to e-commerce platforms with 94 sightings and critical rating. Other notable entries include ASP.NET Core 8.0 (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55315"target="_blank" rel="noopener"&gt;CVE-2025-55315&lt;/a&gt;), D-Link DIR-645 (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;), Cisco IOS (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20352"target="_blank" rel="noopener"&gt;CVE-2025-20352&lt;/a&gt;), and Zyxel p660hn-t1a_v1 (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;), which remain high or critical in severity.&lt;/p&gt;
&lt;p&gt;In parallel, updates to major Known Exploited Vulnerabilities (KEV) catalogs, particularly the CISA list, reveal additional critical entries. VMware VCF operations (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-41244"target="_blank" rel="noopener"&gt;CVE-2025-41244&lt;/a&gt;) and XWiki Platform (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24893"target="_blank" rel="noopener"&gt;CVE-2025-24893&lt;/a&gt;) are newly listed, alongside multiple Dassault Systèmes DELMIA Apriso vulnerabilities (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6205"target="_blank" rel="noopener"&gt;CVE-2025-6205&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6204"target="_blank" rel="noopener"&gt;CVE-2025-6204&lt;/a&gt;), Oracle Configurator (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61884"target="_blank" rel="noopener"&gt;CVE-2025-61884&lt;/a&gt;), and Adobe Commerce (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt;), all showing high or critical severity. Microsoft continues to feature prominently with Windows Server 2019 (CVE-2025-59287) and older Windows versions under active exploitation. Other newly listed KEVs include Apple macOS (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-48503"target="_blank" rel="noopener"&gt;CVE-2022-48503&lt;/a&gt;), Kentico Xperience (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2746"target="_blank" rel="noopener"&gt;CVE-2025-2746&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2747"target="_blank" rel="noopener"&gt;CVE-2025-2747&lt;/a&gt;), and various security flaws in third-party software like MOTEX Lanscope Endpoint Manager and Rapid7 Velociraptor.&lt;/p&gt;
&lt;p&gt;The report also identifies unpublished vulnerabilities detected in the wild. Significant examples include a critical Chrome V8 JavaScript engine flaw (CVE-2025-12036) observed in 12 instances, and multiple remote code execution vulnerabilities in 7-Zip (CVE-2025-11001, CVE-2025-11002). Other unpublished exposures involve OpenCMS XXE attacks, and AMD CPU microcode verification flaws.&lt;/p&gt;
&lt;p&gt;Top weaknesses of the month, summarized via CWE categories, reveal recurring patterns in software development and deployment, emphasizing common attack vectors that continue to be exploited across industries. Contributors’ insights provided context for ongoing campaigns and incidents, including quarterly security notifications from F5, OpenSSL advisories, and the identification of Indicators of Compromise (IOCs) for CVE-2025-59287. Notably, speculation links recent Red Hat OpenShift AI compromises to recently disclosed vulnerabilities, underlining the importance of proactive patching and monitoring.&lt;/p&gt;
&lt;p&gt;Overall, October’s data underscores a continued trend of critical vulnerabilities affecting widely used software and enterprise systems, with both published and unpublished flaws actively exploited. Organizations are strongly encouraged to review KEV listings, prioritize patching based on severity and exposure, and monitor sightings to mitigate immediate threats. The prominence of high-severity vulnerabilities in core infrastructure and cloud services emphasizes the need for continuous vigilance and timely vulnerability management.&lt;/p&gt;
&lt;p&gt;This month’s report features a new section dedicated to &lt;a href="#sightings-forecast"&gt;Sightings Forecast&lt;/a&gt; using a Poisson regression model.&lt;/p&gt;
&lt;h2&gt;Evolution of published CVE in 2025&lt;span class="hx:absolute hx:-mt-20" id="evolution-of-published-cve-in-2025"&gt;&lt;/span&gt;
&lt;a href="#evolution-of-published-cve-in-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/evolution-cve-2025.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/evolution-cve-2025.png" alt="Evolution of published CVE in 2025" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/stats/"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Top 10 Vendors of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/top-10-vendors.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/top-10-vendors.png" alt="Top 10 Vendors of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61882"target="_blank" rel="noopener"&gt;CVE-2025-61882&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;241&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation"target="_blank" rel="noopener"&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation&amp;amp;product=Oracle&amp;#43;Concurrent&amp;#43;Processing"target="_blank" rel="noopener"&gt;Oracle Concurrent Processing&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9963)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;235&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;Server&amp;#43;2019"target="_blank" rel="noopener"&gt;Windows Server 2019&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9565)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49844"target="_blank" rel="noopener"&gt;CVE-2025-49844&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;106&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=redis"target="_blank" rel="noopener"&gt;redis&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=redis&amp;amp;product=redis"target="_blank" rel="noopener"&gt;redis&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.6333)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59489"target="_blank" rel="noopener"&gt;CVE-2025-59489&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;98&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Unity3D"target="_blank" rel="noopener"&gt;Unity3D&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Unity3D&amp;amp;product=Unity&amp;#43;Editor"target="_blank" rel="noopener"&gt;Unity Editor&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.951)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61884"target="_blank" rel="noopener"&gt;CVE-2025-61884&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;95&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation"target="_blank" rel="noopener"&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation&amp;amp;product=Oracle&amp;#43;Configurator"target="_blank" rel="noopener"&gt;Oracle Configurator&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9969)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;94&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Adobe&amp;#43;Commerce"target="_blank" rel="noopener"&gt;Adobe Commerce&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9955)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55315"target="_blank" rel="noopener"&gt;CVE-2025-55315&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;75&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=ASP.NET&amp;#43;Core&amp;#43;8.0"target="_blank" rel="noopener"&gt;ASP.NET Core 8.0&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5387)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.744)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20352"target="_blank" rel="noopener"&gt;CVE-2025-20352&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;63&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=IOS"target="_blank" rel="noopener"&gt;IOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9917)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-1836&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;63&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;zyxel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;p660hn-t1a_v1&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9559)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Sightings forecast&lt;span class="hx:absolute hx:-mt-20" id="sightings-forecast"&gt;&lt;/span&gt;
&lt;a href="#sightings-forecast" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The following visualizations represent the forecasted number of sightings for various vulnerabilities,
using a &lt;a href="https://github.com/vulnerability-lookup/TARDISsight"target="_blank" rel="noopener"&gt;Poisson regression model&lt;/a&gt; with adaptive daily/weekly granularity.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-55315.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-55315.png" alt="Sightings forecast for CVE-2025-55315" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-59287.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-59287.png" alt="Sightings forecast for CVE-2025-59287" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-61882.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-61882.png" alt="Sightings forecast for CVE-2025-61882" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-49844.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-49844.png" alt="Sightings forecast for CVE-2025-49844" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-59489.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/forecast_CVE-2025-59489.png" alt="Sightings forecast for CVE-2025-59489" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-41244"target="_blank" rel="noopener"&gt;CVE-2025-41244&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=VMware"target="_blank" rel="noopener"&gt;VMware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=VMware&amp;amp;product=VCF&amp;#43;operations"target="_blank" rel="noopener"&gt;VCF operations&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.966)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24893"target="_blank" rel="noopener"&gt;CVE-2025-24893&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=xwiki"target="_blank" rel="noopener"&gt;xwiki&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=xwiki&amp;amp;product=xwiki-platform"target="_blank" rel="noopener"&gt;xwiki-platform&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9967)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6205"target="_blank" rel="noopener"&gt;CVE-2025-6205&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dassault&amp;#43;Syst%C3%A8mes"target="_blank" rel="noopener"&gt;Dassault Systèmes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dassault&amp;#43;Syst%C3%A8mes&amp;amp;product=DELMIA&amp;#43;Apriso"target="_blank" rel="noopener"&gt;DELMIA Apriso&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9779)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6204"target="_blank" rel="noopener"&gt;CVE-2025-6204&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dassault&amp;#43;Syst%C3%A8mes"target="_blank" rel="noopener"&gt;Dassault Systèmes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dassault&amp;#43;Syst%C3%A8mes&amp;amp;product=DELMIA&amp;#43;Apriso"target="_blank" rel="noopener"&gt;DELMIA Apriso&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8877)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;24/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Adobe&amp;#43;Commerce"target="_blank" rel="noopener"&gt;Adobe Commerce&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9955)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59287"target="_blank" rel="noopener"&gt;CVE-2025-59287&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;24/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;Server&amp;#43;2019"target="_blank" rel="noopener"&gt;Windows Server 2019&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9565)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61932"target="_blank" rel="noopener"&gt;CVE-2025-61932&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;22/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MOTEX&amp;#43;Inc."target="_blank" rel="noopener"&gt;MOTEX Inc.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=MOTEX&amp;#43;Inc.&amp;amp;product=Lanscope&amp;#43;Endpoint&amp;#43;Manager&amp;#43;%28On-Premises%29&amp;#43;%28Client&amp;#43;program&amp;#43;%28MR%29&amp;#43;and&amp;#43;Detection&amp;#43;agent&amp;#43;%28DA%29%29"target="_blank" rel="noopener"&gt;Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA))&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9162)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61884"target="_blank" rel="noopener"&gt;CVE-2025-61884&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation"target="_blank" rel="noopener"&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation&amp;amp;product=Oracle&amp;#43;Configurator"target="_blank" rel="noopener"&gt;Oracle Configurator&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9969)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-48503"target="_blank" rel="noopener"&gt;CVE-2022-48503&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=macOS"target="_blank" rel="noopener"&gt;macOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9852)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2746"target="_blank" rel="noopener"&gt;CVE-2025-2746&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Kentico"target="_blank" rel="noopener"&gt;Kentico&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Kentico&amp;amp;product=Xperience"target="_blank" rel="noopener"&gt;Xperiences&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9494)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2747"target="_blank" rel="noopener"&gt;CVE-2025-2747&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Kentico"target="_blank" rel="noopener"&gt;Kentico&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Kentico&amp;amp;product=Xperience"target="_blank" rel="noopener"&gt;Xperience&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9852)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33073"target="_blank" rel="noopener"&gt;CVE-2025-33073&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9885)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54253"target="_blank" rel="noopener"&gt;CVE-2025-54253&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Adobe&amp;#43;Experience&amp;#43;Manager"target="_blank" rel="noopener"&gt;Adobe Experience Manager&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9854)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-47827"target="_blank" rel="noopener"&gt;CVE-2025-47827&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=igel"target="_blank" rel="noopener"&gt;igel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=igel&amp;amp;product=igel_os"target="_blank" rel="noopener"&gt;igel_os&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.5969)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6264"target="_blank" rel="noopener"&gt;CVE-2025-6264&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Rapid7"target="_blank" rel="noopener"&gt;Rapid7&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Rapid7&amp;amp;product=Velociraptor"target="_blank" rel="noopener"&gt;Velociraptor&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9267)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-7836"target="_blank" rel="noopener"&gt;CVE-2016-7836&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sky&amp;#43;Co.,&amp;#43;LTD."target="_blank" rel="noopener"&gt;Sky Co., LTD.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sky&amp;#43;Co.,&amp;#43;LTD.&amp;amp;product=SKYSEA&amp;#43;Client&amp;#43;View"target="_blank" rel="noopener"&gt;SKYSEA Client View&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9341)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59230"target="_blank" rel="noopener"&gt;CVE-2025-59230&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9898)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24990"target="_blank" rel="noopener"&gt;CVE-2025-24990&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;11&amp;#43;Version&amp;#43;25H2"target="_blank" rel="noopener"&gt;Windows 11 Version 25H2&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9185)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-43798"target="_blank" rel="noopener"&gt;CVE-2021-43798&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=grafana"target="_blank" rel="noopener"&gt;grafana&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=grafana&amp;amp;product=grafana"target="_blank" rel="noopener"&gt;grafana&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9435)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27915"target="_blank" rel="noopener"&gt;CVE-2025-27915&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;07/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zimbra"target="_blank" rel="noopener"&gt;zimbra&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zimbra&amp;amp;product=collaboration"target="_blank" rel="noopener"&gt;collaboration&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9972)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-3962"target="_blank" rel="noopener"&gt;CVE-2010-3962&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=internet_explorer"target="_blank" rel="noopener"&gt;internet_explorer&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9552)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-61882"target="_blank" rel="noopener"&gt;CVE-2025-61882&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation"target="_blank" rel="noopener"&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Oracle&amp;#43;Corporation&amp;amp;product=Oracle&amp;#43;Concurrent&amp;#43;Processing"target="_blank" rel="noopener"&gt;Oracle Concurrent Processing&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9963)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-22555"target="_blank" rel="noopener"&gt;CVE-2021-22555&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=netapp"target="_blank" rel="noopener"&gt;netapp&lt;/a&gt; / &lt;a href="https://vulnerability.circl.lu/search?vendor=linux"target="_blank" rel="noopener"&gt;linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=netapp&amp;amp;product=c400"target="_blank" rel="noopener"&gt;c400&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9562)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-3765"target="_blank" rel="noopener"&gt;CVE-2010-3765&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=mozilla"target="_blank" rel="noopener"&gt;mozilla&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=mozilla&amp;amp;product=firefox"target="_blank" rel="noopener"&gt;firefox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8923)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-43226"target="_blank" rel="noopener"&gt;CVE-2021-43226&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows&amp;#43;10&amp;#43;Version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9937)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2011-3402"target="_blank" rel="noopener"&gt;CVE-2011-3402&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows_7"target="_blank" rel="noopener"&gt;windows_7&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9359)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2013-3918"target="_blank" rel="noopener"&gt;CVE-2013-3918&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;06/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows_7"target="_blank" rel="noopener"&gt;windows_7&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8313)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4008"target="_blank" rel="noopener"&gt;CVE-2025-4008&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Smartbedded"target="_blank" rel="noopener"&gt;Smartbedded&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Smartbedded&amp;amp;product=MeteoBridge"target="_blank" rel="noopener"&gt;MeteoBridge&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9919)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-7755"target="_blank" rel="noopener"&gt;CVE-2015-7755&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=juniper"target="_blank" rel="noopener"&gt;juniper&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=juniper&amp;amp;product=screenos"target="_blank" rel="noopener"&gt;screenos&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9676)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-1000353"target="_blank" rel="noopener"&gt;CVE-2017-1000353&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=jenkins"target="_blank" rel="noopener"&gt;jenkins&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=jenkins&amp;amp;product=jenkins"target="_blank" rel="noopener"&gt;jenkins&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9902)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2014-6278"target="_blank" rel="noopener"&gt;CVE-2014-6278&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=gnu"target="_blank" rel="noopener"&gt;gnu&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=gnu&amp;amp;product=bash"target="_blank" rel="noopener"&gt;bash&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.4893)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21043"target="_blank" rel="noopener"&gt;CVE-2025-21043&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/10/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Mobile"target="_blank" rel="noopener"&gt;Samsung Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Samsung&amp;#43;Mobile&amp;amp;product=Samsung&amp;#43;Mobile&amp;#43;Devices"target="_blank" rel="noopener"&gt;Samsung Mobile Devices&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9613)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;ENISA&lt;span class="hx:absolute hx:-mt-20" id="enisa"&gt;&lt;/span&gt;
&lt;a href="#enisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;No new entry in October.&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2025&amp;amp;month=10"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/11/top-10-weaknesses.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Click the image for more information.&lt;/p&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;Sightings detected between 2025-10-01 and 2025-10-31 that are associated with unpublished vulnerabilities.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: left"&gt;Vulnerability ID&lt;/th&gt;
&lt;th style="text-align: left"&gt;Occurrences&lt;/th&gt;
&lt;th style="text-align: left"&gt;Comment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12036#sightings"target="_blank" rel="noopener"&gt;CVE-2025-12036&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;12&lt;/td&gt;
&lt;td style="text-align: left"&gt;A New Critical Chrome V8 JavaScript Engine Flaw Enables Attackers to Execute Remote Code on Vulnerable Systems&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11001#sightings"target="_blank" rel="noopener"&gt;CVE-2025-11001&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;9&lt;/td&gt;
&lt;td style="text-align: left"&gt;7-Zip Arbitrary Code Execution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;7&lt;/td&gt;
&lt;td style="text-align: left"&gt;OpenCMS Unauthenticated XXE Vulnerability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-35347#sightings"target="_blank" rel="noopener"&gt;CVE-2024-35347&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;4&lt;/td&gt;
&lt;td style="text-align: left"&gt;AMD CPU Microcode Signature Verification Vulnerability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10230#sightings"target="_blank" rel="noopener"&gt;CVE-2025-10230&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;4&lt;/td&gt;
&lt;td style="text-align: left"&gt;Samba security releases for CVE-2025-10230 and CVE-2025-9640&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11002#sightings"target="_blank" rel="noopener"&gt;CVE-2025-11002&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;4&lt;/td&gt;
&lt;td style="text-align: left"&gt;7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-8h43-rcqj-wpc6#sightings"target="_blank" rel="noopener"&gt;GHSA-8h43-rcqj-wpc6&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;3&lt;/td&gt;
&lt;td style="text-align: left"&gt;Quotes control bypass in Mastodon&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-12490#sightings"target="_blank" rel="noopener"&gt;CVE-2025-12490&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;2&lt;/td&gt;
&lt;td style="text-align: left"&gt;Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24293#sightings"target="_blank" rel="noopener"&gt;CVE-2025-24293&lt;/a&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;2&lt;/td&gt;
&lt;td style="text-align: left"&gt;Rails - Active Storage allowed transformation methods that were potentially unsafe&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/834a30cc-c06c-49b3-9157-eb77f711c73f"target="_blank" rel="noopener"&gt;F5 - K000156572: Quarterly Security Notification (October 2025)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/acbcdcf4-c6b1-4f9e-a2b8-7053fda7238d"target="_blank" rel="noopener"&gt;OpenSSL Security Advisory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/19771c30-1865-418d-8329-9b74748acb52"target="_blank" rel="noopener"&gt;Indicators of Compromise (IOCs) for CVE-2025-59287&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/b7668c06-85ed-4e3f-ab33-77c996b4e48b"target="_blank" rel="noopener"&gt;Growing speculation that the Red Hat compromise may be linked to a recently disclosed vulnerability in Red Hat OpenShift AI&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Lookup and GCVE: A Decentralized Approach to Vulnerability Publishing and Management Workshop at Hack.lu 2025</title><link>http://www.vulnerability-lookup.org/2025/10/24/workshop-at-hack-lu-2025/</link><pubDate>Fri, 24 Oct 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/10/24/workshop-at-hack-lu-2025/</guid><description>
&lt;p&gt;This hands-on workshop at &lt;a href="https://2025.hack.lu/"target="_blank" rel="noopener"&gt;hack.lu 2025&lt;/a&gt; introduced the open-source Vulnerability Lookup project and the Global Common Vulnerabilities and Exposures (GCVE) initiative, two complementary efforts designed to modernize and decentralize the way vulnerabilities are published, shared, and consumed.&lt;/p&gt;
&lt;p&gt;Participants discovered how Vulnerability Lookup acts as a collaborative platform for collecting, enriching, and analyzing vulnerability data, supporting every stage of the vulnerability management lifecycle, from discovery and prioritization to tracking remediation and assessing exposure. The session introduced &lt;a href="https://gcve.eu/"target="_blank" rel="noopener"&gt;GCVE&lt;/a&gt;, a next-generation, decentralized framework for vulnerability identification that empowers organizations to act as GCVE Numbering Authorities (GNAs) with greater autonomy and flexibility.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How to publish and synchronize vulnerabilities using the GCVE and vulnerability-lookup ReST API.&lt;/li&gt;
&lt;li&gt;How decentralized allocation empowers vendors, researchers, and CSIRTs to disclose vulnerabilities more efficiently.&lt;/li&gt;
&lt;li&gt;How to leverage Vulnerability Lookup to support vulnerability triage, enrichment (EPSS, CVSS, Multi KEV), and exposure tracking.&lt;/li&gt;
&lt;li&gt;How Vulnerability Lookup integrates with GCVE to provide real-time insights, cross-references, and analytics.&lt;/li&gt;
&lt;li&gt;Best practices for integrating GCVE and Vulnerability Lookup into your existing vulnerability management workflows.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This post includes all the materials presented during the workshop.&lt;/p&gt;
&lt;h2&gt;Slide decks&lt;span class="hx:absolute hx:-mt-20" id="slide-decks"&gt;&lt;/span&gt;
&lt;a href="#slide-decks" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Part 1 - &lt;a href="https://cra.circl.lu/vl/vl-part-1.pdf"target="_blank" rel="noopener"&gt;https://cra.circl.lu/vl/vl-part-1.pdf&lt;/a&gt; - Vulnerability Lookup and VL-AI - Beyond CVEs: Mastering the Landscape with Vulnerability-Lookup from CVE to CVD&lt;/li&gt;
&lt;li&gt;Part 2 - &lt;a href="https://cra.circl.lu/vl/gcve-part-2.pdf"target="_blank" rel="noopener"&gt;https://cra.circl.lu/vl/gcve-part-2.pdf&lt;/a&gt; - GCVE - GCVE: Global CVE Allocation System Enhancing Flexibility, Scalability, Autonomy, and Resilience in Vulnerability Identification&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Additional References&lt;span class="hx:absolute hx:-mt-20" id="additional-references"&gt;&lt;/span&gt;
&lt;a href="#additional-references" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability-lookup.org/"target="_blank" rel="noopener"&gt;Website&lt;/a&gt; and &lt;a href="https://www.vulnerability-lookup.org/"target="_blank" rel="noopener"&gt;repository of vulnerability-lookup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;vulnerability-lookup instance at CIRCL (GNA-1) - &lt;a href="https://vulnerability.circl.lu/"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/api/"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/api/&lt;/a&gt; - Vulnerability-Lookup API&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulnerability-lookup.org/nis2-directive/"target="_blank" rel="noopener"&gt;https://www.vulnerability-lookup.org/nis2-directive/&lt;/a&gt; - Vulnerability-Lookup and NIS2 Directive Compliance&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulnerability-lookup.org/documentation/feeds.html"target="_blank" rel="noopener"&gt;RSS and Vulnerability-Lookup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulnerability-lookup.org/user-manual/vulnerability-disclosure/"target="_blank" rel="noopener"&gt;Simplified Vulnerability Reporting (aligned with NIS 2 requirements) in Vulnerability-Lookup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Full dumps of vulnerability-lookup sources at CIRCL &lt;a href="https://vulnerability.circl.lu/dumps/"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/dumps/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;HuggingFace CIRCL - &lt;a href="https://huggingface.co/CIRCL"target="_blank" rel="noopener"&gt;https://huggingface.co/CIRCL&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;API Usage of Vulnerability-Lookup&lt;span class="hx:absolute hx:-mt-20" id="api-usage-of-vulnerability-lookup"&gt;&lt;/span&gt;
&lt;a href="#api-usage-of-vulnerability-lookup" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Core API&lt;span class="hx:absolute hx:-mt-20" id="core-api"&gt;&lt;/span&gt;
&lt;a href="#core-api" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Usage&lt;span class="hx:absolute hx:-mt-20" id="usage"&gt;&lt;/span&gt;
&lt;a href="#usage" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Backward compatible with &lt;code&gt;cve-search&lt;/code&gt; (originally developed in late 2012)&lt;/li&gt;
&lt;li&gt;Fully documented, paginated and JSON-Schema validated API&lt;br&gt;
Documentation: &lt;a href="https://vulnerability.circl.lu/api/"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/api/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The UI and core features of Vulnerability-Lookup are built on top of the API&lt;/li&gt;
&lt;li&gt;Sighting tools and satellite projects leverage the same API&lt;br&gt;
&lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;https://www.vulnerability-lookup.org/user-manual/sightings/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Used by &lt;strong&gt;Vulnogram&lt;/strong&gt;, bundled into Vulnerability-Lookup, to manage security advisories&lt;/li&gt;
&lt;li&gt;Supports synchronization between Vulnerability-Lookup instances (in progress)&lt;/li&gt;
&lt;li&gt;Supports &lt;strong&gt;MISP Taxonomy&lt;/strong&gt; for various objects including comments&lt;br&gt;
&lt;a href="https://www.misp-project.org/taxonomies.html#_vulnerability_3"target="_blank" rel="noopener"&gt;https://www.misp-project.org/taxonomies.html#_vulnerability_3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Used as reference implementation for &lt;a href="https://gcve.eu/bcp/gcve-bcp-03/#http-rest-api"target="_blank" rel="noopener"&gt;GCVE-BCP-03&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Correlations&lt;span class="hx:absolute hx:-mt-20" id="correlations"&gt;&lt;/span&gt;
&lt;a href="#correlations" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Related vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="related-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#related-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/vulnerability/CVE-2015-2051?with_linked=true&amp;#39;&lt;/span&gt; &lt;span class="se"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="se"&gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;keys&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;containers&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cveMetadata&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dataType&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dataVersion&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability-lookup:linked&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h4&gt;Correlation sources&lt;span class="hx:absolute hx:-mt-20" id="correlation-sources"&gt;&lt;/span&gt;
&lt;a href="#correlation-sources" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/vulnerability/CVE-2015-2051?with_linked=true&amp;#39;&lt;/span&gt; &lt;span class="se"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="se"&gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.[&amp;#34;vulnerability-lookup:linked&amp;#34;] | keys&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cnvd&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;fkie_nvd&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;github&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;gsd&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;variot&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h4&gt;Correlations from GitHub example&lt;span class="hx:absolute hx:-mt-20" id="correlations-from-github-example"&gt;&lt;/span&gt;
&lt;a href="#correlations-from-github-example" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/vulnerability/CVE-2015-2051?with_linked=true&amp;#39;&lt;/span&gt; &lt;span class="se"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="se"&gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.[&amp;#34;vulnerability-lookup:linked&amp;#34;][&amp;#34;github&amp;#34;]&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;ghsa-x629-5xff-w7qg&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;schema_version&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1.4.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;id&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;GHSA-x629-5xff-w7qg&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;modified&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2025-10-22T03:30:42Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;published&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2022-05-17T03:11:58Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;aliases&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2015-2051&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;details&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;severity&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVSS_V3&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;score&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;references&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;ADVISORY&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://nvd.nist.gov/vuln/detail/CVE-2015-2051&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;WEB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10282&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;WEB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2051&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;WEB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://www.exploit-db.com/exploits/37171&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;WEB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10051&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;WEB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;http://www.securityfocus.com/bid/72623&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;WEB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;http://www.securityfocus.com/bid/74870&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;database_specific&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;cwe_ids&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;CWE-77&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;severity&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;HIGH&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;github_reviewed&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;github_reviewed_at&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;nvd_published_at&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2015-02-23T17:59:00Z&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h4&gt;Retrieving vulnerability sightings&lt;span class="hx:absolute hx:-mt-20" id="retrieving-vulnerability-sightings"&gt;&lt;/span&gt;
&lt;a href="#retrieving-vulnerability-sightings" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/vulnerability/CVE-2024-5261?with_sightings=true&amp;#39;&lt;/span&gt; &lt;span class="se"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="se"&gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.[&amp;#34;vulnerability-lookup:sightings&amp;#34;]&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;eec2c8fd-f664-4e73-b3f5-651db5fa4f3f&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vulnerability_lookup_origin&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1a89b78e-f703-45f3-bb86-59eb712668bd&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;author&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;9f56dd64-161d-43a6-b9c3-555944290a09&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;cve-2024-5261&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;seen&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;source&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://mastodon.social/users/bagder/statuses/113984646246260950&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;creation_timestamp&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2025-02-11T09:54:37.066650Z&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;6de72384-c623-4e70-bd38-1040c4e29bab&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vulnerability_lookup_origin&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1a89b78e-f703-45f3-bb86-59eb712668bd&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;author&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;9f56dd64-161d-43a6-b9c3-555944290a09&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;cve-2024-5261&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;seen&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;source&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://bsky.app/profile/bagder.mastodon.social.ap.brid.gy/post/3lhvfc2enwhl2&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;creation_timestamp&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2025-02-11T10:04:50.326511Z&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;uuid&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;61f4c902-4258-423a-929a-4b473e3d16a0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vulnerability_lookup_origin&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1a89b78e-f703-45f3-bb86-59eb712668bd&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;author&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;9f56dd64-161d-43a6-b9c3-555944290a09&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2024-5261&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;seen&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;source&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://daniel.haxx.se/blog/2025/02/11/disabling-cert-checks-we-have-not-learned-much/&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;creation_timestamp&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2025-02-11T14:00:07.000000Z&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h4&gt;Pivoting via sightings&lt;span class="hx:absolute hx:-mt-20" id="pivoting-via-sightings"&gt;&lt;/span&gt;
&lt;a href="#pivoting-via-sightings" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/sighting/?source=https://daniel.haxx.se/blog/2025/02/11/disabling-cert-checks-we-have-not-learned-much/&amp;#39;&lt;/span&gt; &lt;span class="se"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="se"&gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.data[].vulnerability&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;GHSA-fq29-72jg-5hrj&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;CVE-2024-32928&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;GHSA-9mgx-552f-59p6&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;CVE-2024-56521&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;GHSA-crg3-fjm2-xvpq&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;CVE-2024-5261&amp;#34;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h4&gt;Unpublished advisories&lt;span class="hx:absolute hx:-mt-20" id="unpublished-advisories"&gt;&lt;/span&gt;
&lt;a href="#unpublished-advisories" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Advisories detected via sightings that are not yet published (or rejected):&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/sighting?date_from=2025-10-20&amp;amp;date_to=2025-10-23&amp;amp;advisory_status=unpublished&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq . &lt;span class="p"&gt;|&lt;/span&gt; grep vulnerability&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-54469&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;GHSA-573g-3567-8phg&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-3720&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11702&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-12036&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-12036&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-12036&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-12036&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-10230&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;GHSA-8h43-rcqj-wpc6&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-10230&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-60722&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-12654&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;GHSA-8h43-rcqj-wpc6&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-20727&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-20726&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-20725&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-58148&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-58147&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-58147&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-58148&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11002&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11001&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11001&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2023-42344&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-61431&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-52179&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-52180&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CERTFR-2025-ACT-045&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11002&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11001&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CERTFR-2025-ACT-045&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CERTFR-2025-ACT-045&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11756&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11002&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11001&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-10230&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-10230&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-10230&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;cve-2025-11001&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11002&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11001&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2025-11001&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2023-42344&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vulnerability&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2023-42344&amp;#34;&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Example from the output:&lt;br&gt;
&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-11001#sightings"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/CVE-2025-11001#sightings&lt;/a&gt; -
&amp;ldquo;&lt;a href="https://www.zerodayinitiative.com/advisories/ZDI-25-949/"target="_blank" rel="noopener"&gt;7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability&lt;/a&gt;&amp;rdquo;&lt;/p&gt;
&lt;h2&gt;Endpoints for Statistics&lt;span class="hx:absolute hx:-mt-20" id="endpoints-for-statistics"&gt;&lt;/span&gt;
&lt;a href="#endpoints-for-statistics" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;UI Global statistics - &lt;a href="https://vulnerability.circl.lu/stats/"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/stats/&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Dashboard: &lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;/li&gt;
&lt;li&gt;Most sighted: &lt;a href="https://vulnerability.circl.lu/api/stats/vulnerability/most_sighted"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/api/stats/vulnerability/most_sighted&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Most commented: &lt;a href="https://vulnerability.circl.lu/api/stats/vulnerability/most_commented"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/api/stats/vulnerability/most_commented&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Statistics about CWE&lt;span class="hx:absolute hx:-mt-20" id="statistics-about-cwe"&gt;&lt;/span&gt;
&lt;a href="#statistics-about-cwe" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl -X &lt;span class="s1"&gt;&amp;#39;GET&amp;#39;&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/stats/cwe/most_used?limit=10&amp;amp;output=json&amp;#39;&lt;/span&gt; -H &lt;span class="s1"&gt;&amp;#39;accept: application/json&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-264&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;269.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-399&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;188.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-788&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;140.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-310&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;75.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-840&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;70.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-16&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;61.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-255&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;52.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-354&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;50.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-275&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;48.0&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;#34;cwe&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-648&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;46.0&lt;/span&gt;&lt;span class="p"&gt;}]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3&gt;Statistics about Vendors&lt;span class="hx:absolute hx:-mt-20" id="statistics-about-vendors"&gt;&lt;/span&gt;
&lt;a href="#statistics-about-vendors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl -X &lt;span class="s1"&gt;&amp;#39;GET&amp;#39;&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/stats/vendors/ranking?limit=5&amp;amp;output=json&amp;#39;&lt;/span&gt; -H &lt;span class="s1"&gt;&amp;#39;accept: application/json&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; jq .&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;microsoft&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;115466&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;linux&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;20307&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;red hat&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;19018&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;siemens&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;16787&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;apple&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;11308&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h4&gt;Generate a PDF report from the API&lt;span class="hx:absolute hx:-mt-20" id="generate-a-pdf-report-from-the-api"&gt;&lt;/span&gt;
&lt;a href="#generate-a-pdf-report-from-the-api" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;There are many open format such as &lt;code&gt;markdown&lt;/code&gt;. Complex output pipelines can be added.&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl -s &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/stats/vulnerability/most_sighted?date_from=2025-01-01&amp;amp;output=markdown&amp;#39;&lt;/span&gt; &lt;span class="se"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="se"&gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; pandoc --from&lt;span class="o"&gt;=&lt;/span&gt;markdown --to&lt;span class="o"&gt;=&lt;/span&gt;pdf -o semestrial-report.pdf
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;xdg-open semestrial-report.pdf&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h4&gt;Vendors ranking&lt;span class="hx:absolute hx:-mt-20" id="vendors-ranking"&gt;&lt;/span&gt;
&lt;a href="#vendors-ranking" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl --silent &lt;span class="s1"&gt;&amp;#39;https://vulnerability.circl.lu/api/stats/vendors/ranking?limit=10&amp;amp;output=json&amp;amp;period=2025-09&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;microsoft&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;6155&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;linux&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2110&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;red hat&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;791&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;amd&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;513&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;apple&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;271&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;dell&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;252&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;vasion&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;220&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;google&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;194&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;mitsubishi electric corporation&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;177&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;liferay&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;count&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;137&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
We appreciate your feedback!&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.17.0 released</title><link>http://www.vulnerability-lookup.org/2025/10/13/vulnerability-lookup-2-17-0/</link><pubDate>Mon, 13 Oct 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/10/13/vulnerability-lookup-2-17-0/</guid><description>
&lt;p&gt;We’re happy to announce the release of &lt;strong&gt;Vulnerability-Lookup 2.17.0&lt;/strong&gt; — introducing new data integrations, API improvements, and multiple security and stability fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;New Sightings and Integrations&lt;span class="hx:absolute hx:-mt-20" id="new-sightings-and-integrations"&gt;&lt;/span&gt;
&lt;a href="#new-sightings-and-integrations" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Public PoC Sightings&lt;/strong&gt; — Vulnerabilities with a known public proof of concept can now be tracked directly. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/245"target="_blank" rel="noopener"&gt;#245&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ENISA KEV Catalog&lt;/strong&gt; — Integration of the European Union Agency for Cybersecurity’s Known Exploited Vulnerabilities catalog adds an authoritative new layer of intelligence. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/237"target="_blank" rel="noopener"&gt;#237&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Metasploit Sightings&lt;/strong&gt; — Automatically detect and list vulnerabilities referenced in Metasploit modules. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/228"target="_blank" rel="noopener"&gt;#228&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sploitus RSS&lt;/strong&gt; — Fetch exploit information from Sploitus feeds. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/227"target="_blank" rel="noopener"&gt;#227&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;API Enhancements&lt;span class="hx:absolute hx:-mt-20" id="api-enhancements"&gt;&lt;/span&gt;
&lt;a href="#api-enhancements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Added &lt;strong&gt;bulk DELETE endpoints&lt;/strong&gt; for sightings. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a51492060051b70096832fd56e4638f0093d7a8b"target="_blank" rel="noopener"&gt;commit a514920&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Command-line tools now provide an option to &lt;strong&gt;delete sightings matching a regular expression&lt;/strong&gt;. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/085926082eca30e7b02023c39e2b01a8e36d3a21"target="_blank" rel="noopener"&gt;commit 0859260&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Regex matching for new sightings has been &lt;strong&gt;tightened to require full matches&lt;/strong&gt;, improving data consistency. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/71387fc8c03828e5b5a2ba748f04584e6568ba3d"target="_blank" rel="noopener"&gt;commit 71387fc&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A major focus of 2.17.0 is hardening the platform against potential injection and logic issues. Highlights include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed &lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0005"target="_blank" rel="noopener"&gt;&lt;strong&gt;Reflected XSS&lt;/strong&gt; vulnerabilities&lt;/a&gt; related to unsafe &lt;code&gt;Markup&lt;/code&gt; usage, and a &lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0006"target="_blank" rel="noopener"&gt;&lt;strong&gt;self-XSS&lt;/strong&gt; risk in the admin CPE module&lt;/a&gt; — both responsibly reported by &lt;a href="https://github.com/Wachizungu"target="_blank" rel="noopener"&gt;Jeroen Pinoy&lt;/a&gt;. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/378ccdf95882d1a02576552e26ce222cde0bd636"target="_blank" rel="noopener"&gt;commits 378ccdf&lt;/a&gt;, &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/540366000f2fa27b08bbcc42b1e89927b68b9df6"target="_blank" rel="noopener"&gt;5403660&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Improved handling of &lt;strong&gt;API edge cases&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;/api/search&lt;/code&gt; endpoint errors fixed (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/248"target="_blank" rel="noopener"&gt;#248&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Consistent vendor limits in &lt;code&gt;/vendors/ranking&lt;/code&gt; (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/b958bdbf10947120a952439952a8e61c04982628"target="_blank" rel="noopener"&gt;commit b958bdb&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Better error handling for unknown vulnerabilities (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5eaf64416a1e7c75d2154b0621a6bb9d04ecc0c2"target="_blank" rel="noopener"&gt;commit 5eaf644&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Website improvements:
&lt;ul&gt;
&lt;li&gt;Correct HTTP codes in &lt;code&gt;vulnerability_disclosure.py&lt;/code&gt; (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/4622436a678b56d1c5467eea05238086d9a46bf2"target="_blank" rel="noopener"&gt;commit 4622436&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed duplicate SQLAlchemy filters and decorator issues&lt;/li&gt;
&lt;li&gt;Enforced login for CPE management (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/261"target="_blank" rel="noopener"&gt;PR #261&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Many smaller fixes — escaping for &lt;code&gt;ilike&lt;/code&gt; searches, timeout checks, and improved validation logic across the application.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For a full list of fixes and commits, see the complete &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.17.0"target="_blank" rel="noopener"&gt;changelog&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;🙏 Acknowledgments&lt;span class="hx:absolute hx:-mt-20" id="-acknowledgments"&gt;&lt;/span&gt;
&lt;a href="#-acknowledgments" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A huge thank you to &lt;a href="https://github.com/Wachizungu"target="_blank" rel="noopener"&gt;Jeroen Pinoy&lt;/a&gt; for his thorough code review and valuable security feedback. Your contributions make the platform stronger for everyone.&lt;/p&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.17.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.17.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 A big thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
We appreciate your feedback!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - September 2025</title><link>http://www.vulnerability-lookup.org/2025/10/03/vulnerability-report-september-2025/</link><pubDate>Fri, 03 Oct 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/10/03/vulnerability-report-september-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for September 2025, based on sightings collected from various sources,
including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists,
&lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;,
&lt;a href="https://sploitus.com"target="_blank" rel="noopener"&gt;SPLOITUS&lt;/a&gt;, and more.
For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;September 2025 has been marked by a diverse set of vulnerability sightings across multiple platforms and software ecosystems. The data collected through Vulnerability-Lookup indicates that both newly disclosed and previously known vulnerabilities continued to see active exploitation and discussion in the wild.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10585"target="_blank" rel="noopener"&gt;CVE-2025-10585&lt;/a&gt;, affecting Google Chrome, dominated the reports with &lt;strong&gt;94 sightings&lt;/strong&gt;.
Other frequently sighted vulnerabilities include &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10035"target="_blank" rel="noopener"&gt;CVE-2025-10035&lt;/a&gt; in Fortra’s GoAnywhere MFT and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-42957"target="_blank" rel="noopener"&gt;CVE-2025-42957&lt;/a&gt; in SAP S/4HANA, both of which reflect persistent enterprise-level risks. These instances underscore the continued need for rapid patch deployment and robust monitoring in enterprise environments.&lt;/p&gt;
&lt;p&gt;Network and infrastructure devices also remained a focus for adversaries. Vulnerabilities such as &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-51767"target="_blank" rel="noopener"&gt;CVE-2023-51767&lt;/a&gt; in OpenSSH and several router-specific CVEs like &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt; highlight the ongoing relevance of securing network endpoints against unauthorized access and exploitation. Similarly, Linux-based vulnerabilities, including &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-50264"target="_blank" rel="noopener"&gt;CVE-2024-50264&lt;/a&gt;, accounted for a significant number of sightings, reinforcing the importance of kernel updates and system hardening practices.&lt;/p&gt;
&lt;p&gt;From a severity perspective, most sightings fell into the &lt;strong&gt;High&lt;/strong&gt; and &lt;strong&gt;Critical&lt;/strong&gt; categories, with &lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI&lt;/a&gt; confidence scores often exceeding 0.95. This aligns with global observations of attackers prioritizing high-impact targets, such as widely used browsers, enterprise software, and critical network infrastructure. For example, Adobe Commerce, Sitecore Experience Manager, and Microsoft Entra were all associated with vulnerabilities of critical severity, underlining the necessity for organizations to prioritize patching and risk mitigation.&lt;/p&gt;
&lt;p&gt;September 2025 reinforces several key trends in the cybersecurity landscape: high-severity vulnerabilities remain prevalent across browsers, enterprise software, and networking devices; unpublished vulnerabilities are actively exploited; and community-driven data aggregation plays a critical role in timely awareness and response. Organizations are encouraged to review patch management processes, monitor community sightings, and leverage threat intelligence feeds to mitigate exposure to these ongoing threats.&lt;/p&gt;
&lt;p&gt;This month’s report features a new section dedicated to &lt;a href="#known-exploited-vulnerabilities"&gt;Known Exploited Vulnerabilities catalogs&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Top 10 Vendors of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vendors-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vendors-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/10/top-10-vendors.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/10/top-10-vendors.png" alt="Top 10 Vendors of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Top 15 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-15-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-15-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10585"target="_blank" rel="noopener"&gt;CVE-2025-10585&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;94&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9945)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10035"target="_blank" rel="noopener"&gt;CVE-2025-10035&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortra"target="_blank" rel="noopener"&gt;Fortra&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortra&amp;amp;product=GoAnywhere&amp;#43;MFT"target="_blank" rel="noopener"&gt;GoAnywhere MFT&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9076)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-42957"target="_blank" rel="noopener"&gt;CVE-2025-42957&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;71&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAP_SE"target="_blank" rel="noopener"&gt;SAP_SE&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAP_SE&amp;amp;product=SAP&amp;#43;S/4HANA&amp;#43;%28Private&amp;#43;Cloud&amp;#43;or&amp;#43;On-Premise%29"target="_blank" rel="noopener"&gt;SAP S/4HANA (Private Cloud or On-Premise)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9849)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55241"target="_blank" rel="noopener"&gt;CVE-2025-55241&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;68&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Entra"target="_blank" rel="noopener"&gt;Microsoft Entrac&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.4512)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54236"target="_blank" rel="noopener"&gt;CVE-2025-54236&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe"target="_blank" rel="noopener"&gt;Adobe&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Adobe&amp;amp;product=Adobe&amp;#43;Commerce"target="_blank" rel="noopener"&gt;Adobe Commerce&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9679)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-50264"target="_blank" rel="noopener"&gt;CVE-2024-50264&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9854)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;58&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.4993)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-51767"target="_blank" rel="noopener"&gt;CVE-2023-51767&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;57&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=openssh"target="_blank" rel="noopener"&gt;openssh&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=openssh&amp;amp;product=openssh"target="_blank" rel="noopener"&gt;openssh&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5824)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;57&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;zyxel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v2"target="_blank" rel="noopener"&gt;p660hn-t1a_v2&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9679)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43300"target="_blank" rel="noopener"&gt;CVE-2025-43300&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;54&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=iOS&amp;#43;and&amp;#43;iPadOS"target="_blank" rel="noopener"&gt;iOS and iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9548)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55177"target="_blank" rel="noopener"&gt;CVE-2025-55177&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;53&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Facebook"target="_blank" rel="noopener"&gt;Facebook&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Facebook&amp;amp;product=WhatsApp&amp;#43;Desktop&amp;#43;for&amp;#43;Mac"target="_blank" rel="noopener"&gt;WhatsApp Desktop for Mac&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5006)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;51&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks"target="_blank" rel="noopener"&gt;dasannetworks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks&amp;amp;product=gpon_router"target="_blank" rel="noopener"&gt;gpon_router&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9522)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-1555"target="_blank" rel="noopener"&gt;CVE-2016-1555&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;49&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=netgear"target="_blank" rel="noopener"&gt;netgear&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=netgear&amp;amp;product=wnap320"target="_blank" rel="noopener"&gt;wnap320&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9159)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2033"target="_blank" rel="noopener"&gt;CVE-2025-20333&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;48&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=code-projects"target="_blank" rel="noopener"&gt;code-projects&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=code-projects&amp;amp;product=Blood&amp;#43;Bank&amp;#43;Management&amp;#43;System"target="_blank" rel="noopener"&gt;Blood Bank Management System&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9945)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53690"target="_blank" rel="noopener"&gt;CVE-2025-53690&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;44&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sitecore"target="_blank" rel="noopener"&gt;Sitecore&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sitecore&amp;amp;product=Experience&amp;#43;Manager&amp;#43;%28XM%29"target="_blank" rel="noopener"&gt;Experience Manager (XM)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9573)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Known Exploited Vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="known-exploited-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#known-exploited-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;New entries have been added to major Known Exploited Vulnerabilities catalogs.&lt;/p&gt;
&lt;h3&gt;CISA&lt;span class="hx:absolute hx:-mt-20" id="cisa"&gt;&lt;/span&gt;
&lt;a href="#cisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-59689"target="_blank" rel="noopener"&gt;CVE-2025-59689&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=IOS"target="_blank" rel="noopener"&gt;IOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.8045)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10035"target="_blank" rel="noopener"&gt;CVE-2025-10035&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortra"target="_blank" rel="noopener"&gt;Fortra&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortra&amp;amp;product=GoAnywhere&amp;#43;MFT"target="_blank" rel="noopener"&gt;GoAnywhere MFT&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9076)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32463"target="_blank" rel="noopener"&gt;CVE-2025-32463&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sudo&amp;#43;project"target="_blank" rel="noopener"&gt;Sudo project&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sudo&amp;#43;project&amp;amp;product=Sudo"target="_blank" rel="noopener"&gt;Sudo&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.5599)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-21311"target="_blank" rel="noopener"&gt;CVE-2021-21311&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vrana"target="_blank" rel="noopener"&gt;vrana&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vrana&amp;amp;product=adminer"target="_blank" rel="noopener"&gt;adminer&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.6111)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20352"target="_blank" rel="noopener"&gt;CVE-2025-20352&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=IOS"target="_blank" rel="noopener"&gt;IOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9912)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20333"target="_blank" rel="noopener"&gt;CVE-2025-20333&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;25/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Adaptive&amp;#43;Security&amp;#43;Appliance&amp;#43;%28ASA%29&amp;#43;Software"target="_blank" rel="noopener"&gt;Cisco Adaptive Security Appliance (ASA) Software&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9823)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20362"target="_blank" rel="noopener"&gt;CVE-2025-20362&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;25/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Adaptive&amp;#43;Security&amp;#43;Appliance&amp;#43;%28ASA%29&amp;#43;Software"target="_blank" rel="noopener"&gt;Cisco Adaptive Security Appliance (ASA) Software&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9948)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-10585"target="_blank" rel="noopener"&gt;CVE-2025-10585&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;23/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9945)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5086"target="_blank" rel="noopener"&gt;CVE-2025-5086&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;11/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dassault&amp;#43;Syst%C3%A8mes"target="_blank" rel="noopener"&gt;Dassault Systèmes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Dassault&amp;#43;Syst%C3%A8mes&amp;amp;product=DELMIA&amp;#43;Apriso"target="_blank" rel="noopener"&gt;DELMIA Apriso&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9632)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53690"target="_blank" rel="noopener"&gt;CVE-2025-53690&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sitecore"target="_blank" rel="noopener"&gt;Sitecore&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Sitecore&amp;amp;product=Experience&amp;#43;Manager&amp;#43;%28XM%29"target="_blank" rel="noopener"&gt;Experience Manager (XM)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9573)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48543"target="_blank" rel="noopener"&gt;CVE-2025-48543&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Android"target="_blank" rel="noopener"&gt;Android&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9709)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-38352"target="_blank" rel="noopener"&gt;CVE-2025-38352&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;04/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8176)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-50224"target="_blank" rel="noopener"&gt;CVE-2023-50224&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;03/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TP-Link"target="_blank" rel="noopener"&gt;TP-Link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TP-Link&amp;amp;product=TL-WR841N"target="_blank" rel="noopener"&gt;TL-WR841N&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9651)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9377"target="_blank" rel="noopener"&gt;CVE-2025-9377&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;03/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TP-Link&amp;#43;Systems&amp;#43;Inc."target="_blank" rel="noopener"&gt;TP-Link Systems Inc.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TP-Link&amp;#43;Systems&amp;#43;Inc.&amp;amp;product=Archer&amp;#43;C7%28EU%29&amp;#43;V2"target="_blank" rel="noopener"&gt;Archer C7(EU) V2&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9895)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2020-24363"target="_blank" rel="noopener"&gt;CVE-2020-24363&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;02/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=TP-Link"target="_blank" rel="noopener"&gt;TP-Link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=tp-link&amp;amp;product=tl-wa855re"target="_blank" rel="noopener"&gt;tl-wa855re&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9407)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;ENISA&lt;span class="hx:absolute hx:-mt-20" id="enisa"&gt;&lt;/span&gt;
&lt;a href="#enisa" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE ID&lt;/th&gt;
&lt;th&gt;Date Added&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25231"target="_blank" rel="noopener"&gt;CVE-2025-25231&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;09/09/25&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Omnissa"target="_blank" rel="noopener"&gt;Omnissa&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Omnissa&amp;amp;product=Omnissa&amp;#43;Workspace&amp;#43;ONE&amp;#43;UEM"target="_blank" rel="noopener"&gt;Omnissa Workspace ONE UEM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8877)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2025&amp;amp;month=09"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/10/top-10-weaknesses.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Click the image for more information.&lt;/p&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;Sightings detected between 2025-09-01 and 2025-09-30 that are associated with unpublished vulnerabilities.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Occurrences&lt;/th&gt;
&lt;th&gt;Comment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344 &lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;&lt;a href="https://blog.qualys.com/product-tech/2023/12/08/opencms-unauthenticated-xxe-vulnerability-cve-2023-42344"target="_blank" rel="noopener"&gt;OpenCMS Unauthenticated XXE Vulnerability&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30333#sightings"target="_blank" rel="noopener"&gt;CVE-2025-30333&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27225#sightings"target="_blank" rel="noopener"&gt;CVE-2025-27225&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27225.yaml"target="_blank" rel="noopener"&gt;Nuclei template&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27222#sightings"target="_blank" rel="noopener"&gt;CVE-2025-27222&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14414#sightings"target="_blank" rel="noopener"&gt;CVE-2025-14414&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://portallinuxferramentas.blogspot.com/2025/09/critical-oracle-linux-7-squid-security.html"target="_blank" rel="noopener"&gt;Oracle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2011-2553#sightings"target="_blank" rel="noopener"&gt;CVE-2011-2553&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://sploitus.com/exploit?id=16427382-85F1-528A-A46D-015D6D49E48B"target="_blank" rel="noopener"&gt;Exploit (SPLOITUS) source code not published&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-56708"target="_blank" rel="noopener"&gt;CVE-2025-56708&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://sploitus.com/exploit?id=257FED44-A54B-5842-A9EF-409B92DE6D91"target="_blank" rel="noopener"&gt;Exploit (SPLOITUS)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55817"target="_blank" rel="noopener"&gt;CVE-2025-55817&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;a href="https://sploitus.com/exploit?id=C59B5031-D763-5E6B-B7E5-1EE0FCC97772"target="_blank" rel="noopener"&gt;Exploit (SPLOITUS)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Continuous Exploitation&lt;span class="hx:absolute hx:-mt-20" id="continuous-exploitation"&gt;&lt;/span&gt;
&lt;a href="#continuous-exploitation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/cve-2024-28995#sightings"target="_blank" rel="noopener"&gt;CVE-2024-28995&lt;/a&gt; - &lt;a href="https://vulnerability.circl.lu/search?vendor=SolarWinds&amp;#43;&amp;amp;product=SolarWinds&amp;#43;Serv-U&amp;#43;"target="_blank" rel="noopener"&gt;SolarWinds Serv-U &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/cve-2019-1653#sightings"target="_blank" rel="noopener"&gt;CVE-2019-1653&lt;/a&gt; - &lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco&amp;#43;Small&amp;#43;Business&amp;#43;RV&amp;#43;Series&amp;#43;Router&amp;#43;Firmware"target="_blank" rel="noopener"&gt;Cisco Small Business RV Series Router Firmware&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/43ff9e04-da8f-45fe-a06a-e8f9b84a2d14"target="_blank" rel="noopener"&gt;SAP Security Patch Day - September 2025&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/289697c2-61dc-410f-8343-aba0be87728d"target="_blank" rel="noopener"&gt;npm.js - account qix and duckdb_admin compromised and associated CVEs allocated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/0878ff81-bcad-48b4-b1e5-06b610a5939d"target="_blank" rel="noopener"&gt;Cisco AnyConnect/ASA - vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/b9b7b7f7-7795-4351-bb65-6204702ae05d"target="_blank" rel="noopener"&gt;Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.16.0 released</title><link>http://www.vulnerability-lookup.org/2025/09/19/vulnerability-lookup-2-16-0/</link><pubDate>Fri, 19 Sep 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/09/19/vulnerability-lookup-2-16-0/</guid><description>
&lt;p&gt;We’re delighted to announce the release of Vulnerability-Lookup 2.16.0 — packed with exciting new features!&lt;/p&gt;
&lt;video class="video-shortcode" preload="auto" controls&gt;
&lt;source src="http://www.vulnerability-lookup.org/images/news/2025/09/Vulnerability-Lookup-2.16.0.mp4" type="video/webm"&gt;
There should have been a video here but your browser does not seem
to support it.
&lt;/video&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/09/stats-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/09/stats-1.png" alt="Statistics page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/09/stats-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/09/stats-2.png" alt="Statistics page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/09/stats-3.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/09/stats-3.png" alt="Statistics page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/09/search-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/09/search-1.png" alt="Search page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Backend&lt;span class="hx:absolute hx:-mt-20" id="backend"&gt;&lt;/span&gt;
&lt;a href="#backend" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Introduced &lt;strong&gt;source-scoped kvrocks counters&lt;/strong&gt; and &lt;strong&gt;source-scoped sorted indexes&lt;/strong&gt; for
vulnerability advisories by state (&lt;code&gt;published&lt;/code&gt;, &lt;code&gt;updated&lt;/code&gt;, &lt;code&gt;reserved&lt;/code&gt;).
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/211"target="_blank" rel="noopener"&gt;#211&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/215"target="_blank" rel="noopener"&gt;PR #215&lt;/a&gt;)&lt;br&gt;
Examples of newly available queries:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;GET published:count:github:2025-09&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ZREVRANGE index:csaf_certbund:published 0 9 WITHSCORES&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ZREVRANGE vendors:ranking:2025-08 0 9 WITHSCORES&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Added feeders for &lt;strong&gt;CERT-FR Avis&lt;/strong&gt; and &lt;strong&gt;CERT-FR Alerte&lt;/strong&gt;.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/b99291fcc2a239fa66637b783ff019434e34cab6"target="_blank" rel="noopener"&gt;b99291f&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;API&lt;span class="hx:absolute hx:-mt-20" id="api"&gt;&lt;/span&gt;
&lt;a href="#api" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;strong&gt;Stats API endpoint&lt;/strong&gt; now delivers statistics on &lt;strong&gt;CVE publications&lt;/strong&gt;, with
filters available by source, date, and advisory state. These new endpoints leverage the new
indexes provided by the kvrocks backend. The result can be returned as JSON (default) or Markdown table.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0d153edea14e98b31d18017807cdb33b1d953b8e"target="_blank" rel="noopener"&gt;0d153ed&lt;/a&gt;)&lt;/p&gt;
&lt;h3&gt;Frontend&lt;span class="hx:absolute hx:-mt-20" id="frontend"&gt;&lt;/span&gt;
&lt;a href="#frontend" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Added &lt;strong&gt;a new public statistics page&lt;/strong&gt; displaying various insights on CVE publications.
This new page features several interactive charts powered by the new Stats API endpoints.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0d153edea14e98b31d18017807cdb33b1d953b8e"target="_blank" rel="noopener"&gt;0d153ed&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/c842876a11d85f67d8324f360b477396a339e852"target="_blank" rel="noopener"&gt;c842876&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Added &lt;strong&gt;XSLT support&lt;/strong&gt; for various RSS/Atom feeds.
The XSLT is injected immediately after feed generation, before delivery to the user.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/241c6cadb7d7e4a8af19892399eae7b0d8b0c8a7"target="_blank" rel="noopener"&gt;241c6ca&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Migration Notes&lt;span class="hx:absolute hx:-mt-20" id="migration-notes"&gt;&lt;/span&gt;
&lt;a href="#migration-notes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;To reset the indexes, you can execute &lt;code&gt;bin/index_vulnerabilities.py&lt;/code&gt; which is using various
reindexing utilities. This will delete indexes and counters! Alternatively, you can rerun the
appropriate feeder with the &lt;code&gt;--reimport&lt;/code&gt; parameter.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Improved &lt;strong&gt;search page&lt;/strong&gt;:
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/82b9f95e298ba6f2c495b1987b5183bfec2e7e03"target="_blank" rel="noopener"&gt;82b9f95&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f9f5c588fa23f876b0fdc1f1b46c67871f73bb1a"target="_blank" rel="noopener"&gt;f9f5c58&lt;/a&gt;)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Filtering on sources, vendors, and products.&lt;/li&gt;
&lt;li&gt;Sorting based on advisory state (reserved, published, updated) and order (ascending/descending).&lt;/li&gt;
&lt;li&gt;Displaying all vulnerabilities related to a vendor with pagination (without specifying a product).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Improved &lt;strong&gt;recent page&lt;/strong&gt;: vulnerabilities from multiple sources can now be sorted by publication or update date.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/df1e4725cc23d90a64b84ebe7cdf909580bf58bb"target="_blank" rel="noopener"&gt;df1e472c&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Improved &lt;strong&gt;admin dashboard&lt;/strong&gt; for user management.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/221"target="_blank" rel="noopener"&gt;#221&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Improved &lt;strong&gt;Vulnerability API endpoint&lt;/strong&gt;: The GET List endpoint now provides more advanced filtering by source and advisory state.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0d153edea14e98b31d18017807cdb33b1d953b8e"target="_blank" rel="noopener"&gt;0d153ed&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Various improvements related to the vulnerability description pages.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;NDJSON data dumps: fixed an issue where dumps did not actually contain newlines.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/218"target="_blank" rel="noopener"&gt;#218&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Prevent reimport of already ingested vulnerabilities from flaky CSAF sources.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1848619cda244e98f65a65d8d7e13236e7c51384"target="_blank" rel="noopener"&gt;#1848619&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.16.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.16.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 A big thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
We appreciate your feedback!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - August 2025</title><link>http://www.vulnerability-lookup.org/2025/09/11/vulnerability-report-august-2025/</link><pubDate>Thu, 11 Sep 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/09/11/vulnerability-report-august-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for August 2025, based on sightings collected from various sources, including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists, &lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;, and more. For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;August 2025 saw continued activity across a range of products and vendors, with WinRAR, Microsoft &lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Exchange&amp;#43;Server&amp;#43;Subscription&amp;#43;Edition&amp;#43;RTM"target="_blank" rel="noopener"&gt;Exchange&lt;/a&gt; (the previous month highlighted Microsoft SharePoint), and NetScaler ADC leading the sightings. Notably, several critical vulnerabilities were actively exploited, including &lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler&amp;amp;product=ADC"target="_blank" rel="noopener"&gt;NetScaler ADC&lt;/a&gt; (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6543"target="_blank" rel="noopener"&gt;CVE-2025-6543&lt;/a&gt; and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;) and &lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiSIEM"target="_blank" rel="noopener"&gt;FortiSIEM&lt;/a&gt; (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25256"target="_blank" rel="noopener"&gt;CVE-2025-25256&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Web applications remain a frequent target, with cross-site scripting (&lt;a href="https://vulnerability.circl.lu/cwes/CWE-79"target="_blank" rel="noopener"&gt;CWE-79&lt;/a&gt;) and SQL injection (&lt;a href="https://vulnerability.circl.lu/cwes/CWE-89"target="_blank" rel="noopener"&gt;CWE-89&lt;/a&gt;) dominating the weakness landscape. The report also highlights unpublished vulnerabilities that attracted attention, suggesting ongoing targeted exploitation and zero-day activity.&lt;/p&gt;
&lt;p&gt;Overall, the month emphasizes the importance of timely patching, monitoring for &lt;a href="#continuous-exploitation"&gt;continuous exploitation&lt;/a&gt;, and vigilance against both well-known and &lt;a href="#most-wanted-vulnerabilities"&gt;emerging threats&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8088"target="_blank" rel="noopener"&gt;CVE-2025-8088&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;193&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=win.rar&amp;#43;GmbH"target="_blank" rel="noopener"&gt;win.rar GmbH&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=win.rar&amp;#43;GmbH&amp;amp;product=WinRAR"target="_blank" rel="noopener"&gt;WinRAR&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9824)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53786"target="_blank" rel="noopener"&gt;CVE-2025-53786&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;175&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft&amp;#43;Exchange&amp;#43;Server&amp;#43;Subscription&amp;#43;Edition&amp;#43;RTM"target="_blank" rel="noopener"&gt;Microsoft Exchange Server Subscription Edition RTM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.8193)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-43300"target="_blank" rel="noopener"&gt;CVE-2025-43300&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;128&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=macOS"target="_blank" rel="noopener"&gt;macOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.4233)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6543"target="_blank" rel="noopener"&gt;CVE-2025-6543&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;111&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler"target="_blank" rel="noopener"&gt;NetScaler&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler&amp;amp;product=ADC"target="_blank" rel="noopener"&gt;ADC&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9614)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25256"target="_blank" rel="noopener"&gt;CVE-2025-25256&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiSIEM"target="_blank" rel="noopener"&gt;FortiSIEM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.6508)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9074"target="_blank" rel="noopener"&gt;CVE-2025-9074&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;65&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Docker"target="_blank" rel="noopener"&gt;Docker&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Docker&amp;amp;product=Docker&amp;#43;Desktop"target="_blank" rel="noopener"&gt;Docker Desktop&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8172)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.54)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;61&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;zyxel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v2"target="_blank" rel="noopener"&gt;p660hn-t1a_v2&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9298)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;59&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAP_SE"target="_blank" rel="noopener"&gt;SAP_SE&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAP_SE&amp;amp;product=SAP&amp;#43;NetWeaver&amp;#43;%28Visual&amp;#43;Composer&amp;#43;development&amp;#43;server%29"target="_blank" rel="noopener"&gt;SAP NetWeaver (Visual Composer development server)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9607)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;52&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler"target="_blank" rel="noopener"&gt;NetScaler&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler&amp;amp;product=ADC"target="_blank" rel="noopener"&gt;ADC&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.964)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/cwes/?year=2025&amp;amp;month=08"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/09/top-cwe.png" alt="Top 10 Weaknesses of the Month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CWE&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-79"target="_blank" rel="noopener"&gt;CWE-79&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;639&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-89"target="_blank" rel="noopener"&gt;CWE-89&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;374&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-74"target="_blank" rel="noopener"&gt;CWE-74&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;282&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-94"target="_blank" rel="noopener"&gt;CWE-94&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;236&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-121"target="_blank" rel="noopener"&gt;CWE-121&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;206&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-78"target="_blank" rel="noopener"&gt;CWE-78&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;165&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-416"target="_blank" rel="noopener"&gt;CWE-416&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;157&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-122"target="_blank" rel="noopener"&gt;CWE-122&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;157&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-116"target="_blank" rel="noopener"&gt;CWE-119&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;150&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-22"target="_blank" rel="noopener"&gt;CWE-22&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;140&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;Sightings detected between 2025-08-01 and 2025-08-31 that are associated with unpublished vulnerabilities.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Occurrences&lt;/th&gt;
&lt;th&gt;Comment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=alkacon&amp;amp;product=opencms"target="_blank" rel="noopener"&gt;OpenCMS&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-28080#sightings"target="_blank" rel="noopener"&gt;CVE-2024-28080&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=gitblit&amp;amp;product=gitblit"target="_blank" rel="noopener"&gt;Gitblit&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-42m8-jxr4-976p#sightings"target="_blank" rel="noopener"&gt;GHSA-42m8-jxr4-976p&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;a href="https://github.com/WilderForge/WilderForge/security/advisories/GHSA-42m8-jxr4-976p"target="_blank" rel="noopener"&gt;Wildermyth&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9040#sightings"target="_blank" rel="noopener"&gt;CVE-2025-9040&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Workhorse - &lt;a href="https://vulnerability.circl.lu/bundle/6b6e4418-513f-4750-b0bf-8e6f3ebf62dc"target="_blank" rel="noopener"&gt;bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9037#sightings"target="_blank" rel="noopener"&gt;CVE-2025-9037&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Workhorse - &lt;a href="https://vulnerability.circl.lu/bundle/6b6e4418-513f-4750-b0bf-8e6f3ebf62dc"target="_blank" rel="noopener"&gt;bundle&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Unpublished vulnerabilities with limited sightings:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability ID&lt;/th&gt;
&lt;th&gt;Occurrences&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-34918#sightings"target="_blank" rel="noopener"&gt;CVE-2023-34918&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55117#sightings"target="_blank" rel="noopener"&gt;CVE-2025-55117&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-14553#sightings"target="_blank" rel="noopener"&gt;CVE-2025-14553&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-55177#sightings"target="_blank" rel="noopener"&gt;CVE-2024-55177&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-5pm9-r2m8-rcmj#sightings"target="_blank" rel="noopener"&gt;GHSA-5pm9-r2m8-rcmj&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-m42g-xg4c-5f3h#sightings"target="_blank" rel="noopener"&gt;GHSA-m42g-xg4c-5f3h&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-64qc-9x89-rx5j#sightings"target="_blank" rel="noopener"&gt;GHSA-64qc-9x89-rx5j&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-7719#sightings"target="_blank" rel="noopener"&gt;CVE-2025-7719&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-c2gv-xgf5-5cc2#sightings"target="_blank" rel="noopener"&gt;GHSA-c2gv-xgf5-5cc2&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-55616#sightings"target="_blank" rel="noopener"&gt;CVE-2025-55616&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-57497#sightings"target="_blank" rel="noopener"&gt;CVE-2025-57497&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25964#sightings"target="_blank" rel="noopener"&gt;CVE-2025-25964&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-545078#sightings"target="_blank" rel="noopener"&gt;CVE-2024-545078&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25987#sightings"target="_blank" rel="noopener"&gt;CVE-2025-25987&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1272#sightings"target="_blank" rel="noopener"&gt;CVE-2025-1272&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21589#sightings"target="_blank" rel="noopener"&gt;CVE-2025-21589&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-26517#sightings"target="_blank" rel="noopener"&gt;CVE-2025-26517&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-9141#sightings"target="_blank" rel="noopener"&gt;CVE-2025-9141&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-wrh9-463x-7wvv#sightings"target="_blank" rel="noopener"&gt;GHSA-wrh9-463x-7wvv&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-46507#sightings"target="_blank" rel="noopener"&gt;CVE-2024-46507&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-54321#sightings"target="_blank" rel="noopener"&gt;CVE-2025-54321&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31143#sightings"target="_blank" rel="noopener"&gt;CVE-2025-31143&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31646#sightings"target="_blank" rel="noopener"&gt;CVE-2025-31646&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27564#sightings"target="_blank" rel="noopener"&gt;CVE-2025-27564&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-r4mf-mr9h-f27m#sightings"target="_blank" rel="noopener"&gt;GHSA-r4mf-mr9h-f27m&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Continuous Exploitation&lt;span class="hx:absolute hx:-mt-20" id="continuous-exploitation"&gt;&lt;/span&gt;
&lt;a href="#continuous-exploitation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt; - OpenCMS
(also in the &amp;ldquo;Most wanted vulnerabilities&amp;rdquo; section)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051#sightings"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt; - D-Link DIR-645 - Sightings from MISP and Shadowserver&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777#sightings"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt; - NetScaler ADC - Sightings from Shadowserver and many more.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424&lt;span class="hx:absolute hx:-mt-20" id="netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2025-7775-cve-2025-7776-and-cve-2025-8424"&gt;&lt;/span&gt;
&lt;a href="#netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2025-7775-cve-2025-7776-and-cve-2025-8424" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;NetScaler ADC and NetScaler Gateway Security Bulletin for &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-7775"target="_blank" rel="noopener"&gt;CVE-2025-7775&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-7776"target="_blank" rel="noopener"&gt;CVE-2025-7776&lt;/a&gt; and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-8424"target="_blank" rel="noopener"&gt;CVE-2025-8424&lt;/a&gt;.&lt;br&gt;
Multiple vulnerabilities have been discovered in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Refer below for further details.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/bundle/6001a8cc-e4a0-48af-9eaf-7967fc09c50e"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Citrix forgot to tell you CVE-2025–6543 has been used as a zero day since May 2025&lt;span class="hx:absolute hx:-mt-20" id="citrix-forgot-to-tell-you-cve-20256543-has-been-used-as-a-zero-day-since-may-2025"&gt;&lt;/span&gt;
&lt;a href="#citrix-forgot-to-tell-you-cve-20256543-has-been-used-as-a-zero-day-since-may-2025" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Back in late June, Citrix posted a patch for CVE-2025–6543, which they described as “Memory overflow vulnerability leading to unintended control flow and Denial of Service”. Denial of service? Piff the magic dragon, who cares.&lt;/p&gt;
&lt;p&gt;No technical details were ever published about the vulnerability. That changes today.&lt;/p&gt;
&lt;p&gt;What they forgot to tell you: it allows remote code execution, it was used to widespread compromise Netscaler remote access systems and maintain network access even after patching, webshells have been deployed, and Citrix knew this and just didn’t mention it.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/comment/4a43bf52-0c47-4127-b278-29316a7c4c3d"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Cache Me If You Can (Sitecore Experience Platform Cache Poisoning to RCE)&lt;span class="hx:absolute hx:-mt-20" id="cache-me-if-you-can-sitecore-experience-platform-cache-poisoning-to-rce"&gt;&lt;/span&gt;
&lt;a href="#cache-me-if-you-can-sitecore-experience-platform-cache-poisoning-to-rce" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The vulnerability affects Sitecore Experience Platform, a widely used Content Management System (CMS). The issue is a cache poisoning attack, which means an attacker can trick the system into storing malicious data in its cache. Later, when the system serves cached content, it unknowingly executes this malicious content.&lt;/p&gt;
&lt;p&gt;In this specific case, the cache poisoning can escalate to remote code execution (RCE), meaning the attacker could run arbitrary code on the server, potentially taking full control of the website and the underlying system.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/bundle/b0453b3f-aa70-494d-8cbf-b4217e22de4a"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Two New feeds from CERT-FR (ANSSI) integrated in Vulnerability-Lookup</title><link>http://www.vulnerability-lookup.org/2025/08/29/certfr-in-vulnerability-lookup/</link><pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/08/29/certfr-in-vulnerability-lookup/</guid><description>
&lt;p&gt;Two New feeds from &lt;a href="https://www.cert.ssi.gouv.fr"target="_blank" rel="noopener"&gt;CERT-FR&lt;/a&gt; are now integrated in Vulnerability-Lookup.&lt;/p&gt;
&lt;p&gt;Thanks to the great work of &lt;a href="https://github.com/Rafiot"target="_blank" rel="noopener"&gt;Raphaël Vinot&lt;/a&gt;, we now have two new feeders:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/recent#certfr_alerte"target="_blank" rel="noopener"&gt;CERT-FR Alerte&lt;/a&gt;, and&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/recent#certfr_avis"target="_blank" rel="noopener"&gt;CERT-FR Avis&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We were impressed by the excellent quality of these feeds, which allowed us to automatically extract impacted products (CPE vendors &amp;amp; names) and references to enrich our Kvrocks indexes.&lt;/p&gt;
&lt;h2&gt;Correlations&lt;span class="hx:absolute hx:-mt-20" id="correlations"&gt;&lt;/span&gt;
&lt;a href="#correlations" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;As with all our sources, advisories from CERT-FR are now automatically correlated with the other 27 (!) sources available on the CIRCL instance:&lt;br&gt;
&lt;a href="https://vulnerability.circl.lu/about#sources"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/about#sources&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Examples of correlations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CERTFR-2024-ALE-013#related"target="_blank" rel="noopener"&gt;Related CVEs for a product from Ivanti from the &amp;ldquo;Alerte&amp;rdquo; CERTFR-2024-ALE-013&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CERTFR-2025-AVI-0732"target="_blank" rel="noopener"&gt;CVE-2025-9478 - vulnerability in Chrome&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Screenshots&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-ale-correlations.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-ale-correlations.png" alt="Sightings correlations" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-ale.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-ale.png" alt="Vulnerability correlations" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-avis.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-avis.png" alt="Impacted products" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Sightings&lt;span class="hx:absolute hx:-mt-20" id="sightings"&gt;&lt;/span&gt;
&lt;a href="#sightings" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can already find sightings tied to CERT-FR advisories. For example, the sightings related to alerts published in 2025:&lt;br&gt;
&lt;a href="https://vulnerability.circl.lu/sightings/?query=CERTFR-2025-ALE"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/sightings/?query=CERTFR-2025-ALE&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Screenshot&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-ale-sightings.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/certfr-ale-sightings.png" alt="List of sightins from CERTFR-2015-ALE" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Contribute&lt;span class="hx:absolute hx:-mt-20" id="contribute"&gt;&lt;/span&gt;
&lt;a href="#contribute" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Have a source you think should be integrated into Vulnerability-Lookup? Let us know!&lt;/p&gt;
&lt;p&gt;Don&amp;rsquo;t hesitate to create an account on our instance: &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/user/signup&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors, and especially to CERT-FR for providing these excellent feeds.&lt;/p&gt;
&lt;h2&gt;References&lt;span class="hx:absolute hx:-mt-20" id="references"&gt;&lt;/span&gt;
&lt;a href="#references" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;The &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup?tab=readme-ov-file#sources-and-default-feeders"target="_blank" rel="noopener"&gt;list of default feeders&lt;/a&gt;, active and ready to use in any Vulnerability-Lookup installation.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup"target="_blank" rel="noopener"&gt;Source code of Vulnerability-Lookup&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.vulnerability-lookup.org/news/"target="_blank" rel="noopener"&gt;News about the project&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Vulnerability Report - July 2025</title><link>http://www.vulnerability-lookup.org/2025/08/23/vulnerability-report-july-2025/</link><pubDate>Sat, 23 Aug 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/08/23/vulnerability-report-july-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for July 2025, based on sightings collected from various sources, including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists, &lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;, and more. For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The final section focuses on exploitations observed through &lt;a href="https://www.shadowserver.org"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;&amp;rsquo;s honeypot network.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The most reported vulnerability this month is &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770"target="_blank" rel="noopener"&gt;CVE-2025-53770&lt;/a&gt;,
a critical flaw in &lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft%20SharePoint%20Enterprise%20Server%202016"target="_blank" rel="noopener"&gt;Microsoft SharePoint Enterprise Server 2016&lt;/a&gt;,
with over 400 sightings. Other high-impact vulnerabilities include &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;
affecting NetScaler ADC, and &lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25257"target="_blank" rel="noopener"&gt;CVE-2025-25257&lt;/a&gt;
in Fortinet FortiWeb, both widely discussed across communities and security feeds.&lt;/p&gt;
&lt;p&gt;Well-known products such as &lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Google Chrome&lt;/a&gt; and&lt;a href="https://vulnerability.circl.lu/search?vendor=wftpserver&amp;amp;product=Wing%20FTP%20Server"target="_blank" rel="noopener"&gt; Wing FTP Server&lt;/a&gt; also appear in the top 10,
along with GitHub advisories like &lt;a href="https://vulnerability.circl.lu/vuln/GHSA-269G-PWP5-87PP"target="_blank" rel="noopener"&gt;GHSA-269G-PWP5-87PP&lt;/a&gt; (JUnit4)
and &lt;a href="https://vulnerability.circl.lu/vuln/GHSA-78WR-2P64-HPWJ"target="_blank" rel="noopener"&gt;GHSA-78WR-2P64-HPWJ&lt;/a&gt; (Apache Commons IO).
This mix shows how both enterprise-grade platforms and widely used open-source projects continue to be targeted.&lt;/p&gt;
&lt;p&gt;The most common weaknesses remain familiar:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-79"target="_blank" rel="noopener"&gt;CWE-79&lt;/a&gt; (Cross-site Scripting) with 747 cases.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-99"target="_blank" rel="noopener"&gt;CWE-89&lt;/a&gt; (SQL Injection) with 710 cases.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-122"target="_blank" rel="noopener"&gt;CWE-122&lt;/a&gt; (Heap-based Buffer Overflow) with 593 cases.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Sighting Count&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770"target="_blank" rel="noopener"&gt;CVE-2025-53770&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;416&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft%20SharePoint%20Enterprise%20Server%202016"target="_blank" rel="noopener"&gt;Microsoft SharePoint Enterprise Server 2016&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.8952)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;267&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler"target="_blank" rel="noopener"&gt;NetScaler&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler&amp;amp;product=ADC"target="_blank" rel="noopener"&gt;ADC&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9621)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25257"target="_blank" rel="noopener"&gt;CVE-2025-25257&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;145&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiWeb"target="_blank" rel="noopener"&gt;FortiWeb&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9819)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6554"target="_blank" rel="noopener"&gt;CVE-2025-6554&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;130&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High (confidence: 0.9928)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-47812"target="_blank" rel="noopener"&gt;CVE-2025-47812&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;129&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=wftpserver"target="_blank" rel="noopener"&gt;wftpserver&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=wftpserver&amp;amp;product=Wing%20FTP%20Server"target="_blank" rel="noopener"&gt;Wing FTP Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical (confidence: 0.9724)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-269G-PWP5-87PP"target="_blank" rel="noopener"&gt;GHSA-269G-PWP5-87PP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;120&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=junit-team"target="_blank" rel="noopener"&gt;junit-team&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=junit-team&amp;amp;product=junit4"target="_blank" rel="noopener"&gt;junit4&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.5366)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-53771"target="_blank" rel="noopener"&gt;CVE-2025-53771&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;104&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft%20SharePoint%20Enterprise%20Server%202016"target="_blank" rel="noopener"&gt;Microsoft SharePoint Enterprise Server 2016&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9689)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49706"target="_blank" rel="noopener"&gt;CVE-2025-49706&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;96&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Microsoft%20SharePoint%20Enterprise%20Server%202016"target="_blank" rel="noopener"&gt;Microsoft SharePoint Enterprise Server 2016&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9689)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-78WR-2P64-HPWJ"target="_blank" rel="noopener"&gt;GHSA-78WR-2P64-HPWJ&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;85&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation&amp;amp;product=Apache%20Commons%20IO"target="_blank" rel="noopener"&gt;Apache Commons IO&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium (confidence: 0.9078)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GHSA-5MG8-W23W-74H3"target="_blank" rel="noopener"&gt;GHSA-5MG8-W23W-74H3&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;84&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google%20LLC"target="_blank" rel="noopener"&gt;Google LLC&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google%20LLC&amp;amp;product=Guava"target="_blank" rel="noopener"&gt;Guava&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Low (confidence: 0.877)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Ghost CVE Report&lt;span class="hx:absolute hx:-mt-20" id="ghost-cve-report"&gt;&lt;/span&gt;
&lt;a href="#ghost-cve-report" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A ghost CVE is a vulnerability identifier that&amp;rsquo;s already popped up in the wild but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.&lt;/p&gt;
&lt;p&gt;The following vulnerabilities were &lt;strong&gt;only&lt;/strong&gt; detected through our sighting tools:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-42344#sightings"target="_blank" rel="noopener"&gt;CVE-2023-42344&lt;/a&gt;, source: The Shadowserver (honeypot/common-vulnerabilities)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-48932#sightings"target="_blank" rel="noopener"&gt;CVE-2025-48932&lt;/a&gt;, source: Bluesky&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These vulnerabilities have not yet been officially published.&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CWE&lt;/th&gt;
&lt;th&gt;Number of vulnerabilities&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-79"target="_blank" rel="noopener"&gt;CWE-79&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;747&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-89"target="_blank" rel="noopener"&gt;CWE-89&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;710&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-122"target="_blank" rel="noopener"&gt;CWE-122&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;593&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-74"target="_blank" rel="noopener"&gt;CWE-74&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;526&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-416"target="_blank" rel="noopener"&gt;CWE-416&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;492&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-119"target="_blank" rel="noopener"&gt;CWE-119&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;397&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-125"target="_blank" rel="noopener"&gt;CWE-125&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;353&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-94"target="_blank" rel="noopener"&gt;CWE-94&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;313&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-434"target="_blank" rel="noopener"&gt;CWE-434&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;216&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-121"target="_blank" rel="noopener"&gt;CWE-121&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;213&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Ruckus network management solutions riddled with unpatched vulnerabilities - Help Net Security&lt;span class="hx:absolute hx:-mt-20" id="ruckus-network-management-solutions-riddled-with-unpatched-vulnerabilities---help-net-security"&gt;&lt;/span&gt;
&lt;a href="#ruckus-network-management-solutions-riddled-with-unpatched-vulnerabilities---help-net-security" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Claroty researcher Noam Moshe has discovered serious vulnerabilities in two Ruckus Networks (formerly Ruckus Wireless) products that may allow attackers to compromise the environments managed by the affected software, Carnegie Mellon University’s CERT Coordination Center (CERT/CC) has warned.&lt;br&gt;
&lt;a href="https://vulnerability.circl.lu/bundle/e6381844-1d85-477e-83f0-f85545c99c27"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)&lt;span class="hx:absolute hx:-mt-20" id="pre-auth-sql-injection-to-rce---fortinet-fortiweb-fabric-connector-cve-2025-25257"&gt;&lt;/span&gt;
&lt;a href="#pre-auth-sql-injection-to-rce---fortinet-fortiweb-fabric-connector-cve-2025-25257" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;An improper neutralization of special elements used in an SQL command (&amp;lsquo;SQL Injection&amp;rsquo;) vulnerability [CWE-89] in Fortinet FortiWeb.&lt;br&gt;
&lt;a href="https://vulnerability.circl.lu/comment/94b37950-f479-444b-bff8-5571bd15eac5"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;VMSA-2025-0013: VMware ESXi, Workstation, Fusion, and Tools updates address multiple vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="vmsa-2025-0013-vmware-esxi-workstation-fusion-and-tools-updates-address-multiple-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#vmsa-2025-0013-vmware-esxi-workstation-fusion-and-tools-updates-address-multiple-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Multiple vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.&lt;br&gt;
&lt;a href="https://vulnerability.circl.lu/bundle/419fd7d2-3c77-4032-b717-747015a7b289"target="_blank" rel="noopener"&gt;More information&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Continuous Exploitation&lt;span class="hx:absolute hx:-mt-20" id="continuous-exploitation"&gt;&lt;/span&gt;
&lt;a href="#continuous-exploitation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/cve-2018-13379"target="_blank" rel="noopener"&gt;CVE-2018-13379&lt;/a&gt; -
&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt; /
&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=Fortinet&amp;#43;FortiOS,&amp;#43;FortiProxy"target="_blank" rel="noopener"&gt;Fortinet FortiOS, FortiProxy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt; -
&lt;a href="https://vulnerability.circl.lu/search?vendor=Huawei&amp;#43;Technologies&amp;#43;Co.,&amp;#43;Ltd."target="_blank" rel="noopener"&gt;Huawei Technologies Co., Ltd.&lt;/a&gt; /
&lt;a href="https://vulnerability.circl.lu/search?vendor=Huawei&amp;#43;Technologies&amp;#43;Co.,&amp;#43;Ltd.&amp;amp;product=HG532"target="_blank" rel="noopener"&gt;HG532&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt; -
&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler"target="_blank" rel="noopener"&gt;NetScaler&lt;/a&gt; /
&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler&amp;amp;product=ADC"target="_blank" rel="noopener"&gt;ADC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.circl.lu/pub/press/20240131"target="_blank" rel="noopener"&gt;Press release&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.15.0 released</title><link>http://www.vulnerability-lookup.org/2025/08/22/vulnerability-lookup-2-15-0/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/08/22/vulnerability-lookup-2-15-0/</guid><description>
&lt;p&gt;We are excited to announce the release of &lt;strong&gt;Vulnerability-Lookup 2.15.0&lt;/strong&gt;!&lt;br&gt;
This version brings new features, performance improvements, and several bug fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Detecting vulnerabilities known only through sightings&lt;span class="hx:absolute hx:-mt-20" id="detecting-vulnerabilities-known-only-through-sightings"&gt;&lt;/span&gt;
&lt;a href="#detecting-vulnerabilities-known-only-through-sightings" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The dashboard now highlights vulnerabilities discovered via our sighting tools, including scraping social networks, MISP, Nuclei templates, Shadowserver, Gist, and more. This gives you better visibility of unpublished advisories.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/dashboard-unpublished-sightings.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/dashboard-unpublished-sightings.png" alt="Unpublished advisory - table" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/list-unpublished-sightings.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/list-unpublished-sightings.png" alt="Unpublished advisory - list" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/unpublished-advisory-with-sightings.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/unpublished-advisory-with-sightings.png" alt="Unpublished advisory - sightings" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Batch user deletion for admins&lt;span class="hx:absolute hx:-mt-20" id="batch-user-deletion-for-admins"&gt;&lt;/span&gt;
&lt;a href="#batch-user-deletion-for-admins" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Admins can now delete multiple users at once using checkboxes and a confirmation modal. CSRF protection is included to ensure safe operations.&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Better logging&lt;/strong&gt;&lt;br&gt;
We improved logging for access, warnings, and errors in the web app, including the HTTP status codes returned in unexpected situations.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/199"target="_blank" rel="noopener"&gt;Issue #199&lt;/a&gt;&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commits"target="_blank" rel="noopener"&gt;Commits: a6b99bf, 9c37e7e, d2e826f&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Faster vendor/product vulnerability searches&lt;/strong&gt;&lt;br&gt;
The search page is now faster thanks to pipelines and pagination. A Bootstrap pagination component has been added when vendor and product are specified.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/aeb6ae0337fcc3b7efebeb94348a9ca82e0cc490"target="_blank" rel="noopener"&gt;Commit aeb6ae0&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/search-vendor.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/search-vendor.png" alt="Search by vendor" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/search-vendor-product.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/search-vendor-product.png" alt="Search by vendor and product" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;New API option&lt;/strong&gt;&lt;br&gt;
Added &lt;code&gt;advisory_status&lt;/code&gt; parameter to the &lt;code&gt;/sighting&lt;/code&gt; endpoint.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/de5873ce2ae555ceaafdaf67e0fefab42c402ad7"target="_blank" rel="noopener"&gt;Commit de5873c&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Faster Organization/Product search&lt;/strong&gt;&lt;br&gt;
The &lt;code&gt;find_vulnerabilities&lt;/code&gt; function now finds matching vulnerabilities for all vendor/product combinations much faster.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/67d25162432531de07e77e3129be5a33c58f9eb8"target="_blank" rel="noopener"&gt;Commit 67d2516&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Search page improvements&lt;/strong&gt;&lt;br&gt;
We made several graphical and functional enhancements to the search page.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commits"target="_blank" rel="noopener"&gt;Commits: 82c6f2d, 0f249d1, 94e53c0&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;About page improvements&lt;/strong&gt;&lt;br&gt;
Better handling of GNAs and a link to the recent activity page.&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commits"target="_blank" rel="noopener"&gt;Commits: 70308f5, 168fcff&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Dashboard updates&lt;/strong&gt;&lt;br&gt;
Various improvements related to recently imported vulnerabilities and new filters in the &amp;ldquo;Evolution for the last month&amp;rdquo; table.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/about-aha.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/about-aha.png" alt="improved about page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/08/recent-aha.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/08/recent-aha.png" alt="Recent - AHA!" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 For the full list of changes, check the GitHub release:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.15.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.15.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 A big thank you to all contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you find any issues or have suggestions, please open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
We appreciate your feedback!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Stay updated on security advisories in real-time by following us on Mastodon:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.14.0 released</title><link>http://www.vulnerability-lookup.org/2025/07/25/vulnerability-lookup-2-14-0/</link><pubDate>Fri, 25 Jul 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/07/25/vulnerability-lookup-2-14-0/</guid><description>
&lt;p&gt;We’re glad to announce verion 2.14.0 of Vulnerability-Lookup!&lt;br&gt;
This version introduces several new features, enhancements, and fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;New Watchlist View&lt;span class="hx:absolute hx:-mt-20" id="new-watchlist-view"&gt;&lt;/span&gt;
&lt;a href="#new-watchlist-view" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;You can now view your monitored products and their related vulnerabilities directly in the browser,
mirroring the structure of email notifications. Authenticated RSS/Atom feeds are available.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/181"target="_blank" rel="noopener"&gt;#181&lt;/a&gt;)&lt;/p&gt;
&lt;video class="video-shortcode" preload="auto" controls&gt;
&lt;source src="http://www.vulnerability-lookup.org/images/news/2025/07/watchlist.webm" type="video/webm"&gt;
There should have been a video here but your browser does not seem
to support it.
&lt;/video&gt;
&lt;p&gt;(enable audio in the screencast)&lt;/p&gt;
&lt;h3&gt;GNA Verification&lt;span class="hx:absolute hx:-mt-20" id="gna-verification"&gt;&lt;/span&gt;
&lt;a href="#gna-verification" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;We added a way to confirm whether a Vulnerability-Lookup instance is officially operated by a GNA.
The information is available on the About page.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/179"target="_blank" rel="noopener"&gt;#179&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/07/gna.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/07/gna.png" alt="GNA Verification" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Optional CVD Process&lt;span class="hx:absolute hx:-mt-20" id="optional-cvd-process"&gt;&lt;/span&gt;
&lt;a href="#optional-cvd-process" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The Coordinated Vulnerability Disclosure module can now be disabled if not applicable to your deployment.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/178"target="_blank" rel="noopener"&gt;#178&lt;/a&gt;)&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Other changes include a smoother post-login experience and a fail-safe around ML-Gateway calls for related vulnerabilities.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/170"target="_blank" rel="noopener"&gt;#170&lt;/a&gt;)&lt;/p&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 To explore the full list of changes, visit the changelog on GitHub:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.14.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.14.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you very much to all the contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.13.0 released</title><link>http://www.vulnerability-lookup.org/2025/07/11/vulnerability-lookup-2-13-0/</link><pubDate>Fri, 11 Jul 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/07/11/vulnerability-lookup-2-13-0/</guid><description>
&lt;p&gt;We’re excited to announce the release of Vulnerability-Lookup 2.13.0!&lt;br&gt;
This version introduces several new features, enhancements, and fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Support for VLAI Severity Classification in Chinese&lt;span class="hx:absolute hx:-mt-20" id="support-for-vlai-severity-classification-in-chinese"&gt;&lt;/span&gt;
&lt;a href="#support-for-vlai-severity-classification-in-chinese" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;For vulnerabilities originating from the CNVD source, Vulnerability-Lookup now leverages the
&lt;a href="https://github.com/vulnerability-lookup/ML-Gateway"target="_blank" rel="noopener"&gt;ML-Gateway&lt;/a&gt; to perform inference using the
&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-chinese-macbert-base"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-severity-classification-chinese-macbert-base&lt;/a&gt; model.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0b85b2d1affb36e3a096120aee0cce797aa52ac3"target="_blank" rel="noopener"&gt;0b85b2d&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/07/cnvd-vl-api.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/07/cnvd-vl-api.png" alt="Support for VLAI Severity Classification in Chinese" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;More information is available on &lt;a href="https://arxiv.org/abs/2507.03607"target="_blank" rel="noopener"&gt;VLAI Severity Classification&lt;/a&gt; (preprint for the 25V4C-TC: 2025 Vulnerability Forecasting Technical Colloquia. Darwin College Cambridge, UK).&lt;/p&gt;
&lt;h3&gt;Easy Access to Mitigations from the Vulnerability View&lt;span class="hx:absolute hx:-mt-20" id="easy-access-to-mitigations-from-the-vulnerability-view"&gt;&lt;/span&gt;
&lt;a href="#easy-access-to-mitigations-from-the-vulnerability-view" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Mitigations derived from CWEs are now directly displayed on the vulnerability details page.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/172"target="_blank" rel="noopener"&gt;#172&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/07/mitigations.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/07/mitigations.png" alt="Easy access to mitigations from the vulnerability view" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Filter Vulnerabilities by CWE via the API&lt;span class="hx:absolute hx:-mt-20" id="filter-vulnerabilities-by-cwe-via-the-api"&gt;&lt;/span&gt;
&lt;a href="#filter-vulnerabilities-by-cwe-via-the-api" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;em&gt;/vulnerability/last&lt;/em&gt; API endpoint now supports filtering results by CWE.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/148"target="_blank" rel="noopener"&gt;#148&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;Example query:&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ curl https://vulnerability.circl.lu/api/vulnerability/last/1?cwe&lt;span class="o"&gt;=&lt;/span&gt;CWE-79 &lt;span class="p"&gt;|&lt;/span&gt; jq .&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Result:&lt;/p&gt;
&lt;div class="hextra-code-block hx:relative hx:mt-6 hx:first:mt-0 hx:group/code"&gt;
&lt;div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dataType&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE_RECORD&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dataVersion&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;5.1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cveMetadata&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cveId&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE-2006-10001&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;assignerOrgId&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1af790b2-7ee1-4545-860a-a788eba489b5&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;state&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;PUBLISHED&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;assignerShortName&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;VulDB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dateReserved&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2023-03-04T10:47:33.154Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;datePublished&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2023-03-05T20:31:03.187Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dateUpdated&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2024-08-07T20:57:41.047Z&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;containers&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cna&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;providerMetadata&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;orgId&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1af790b2-7ee1-4545-860a-a788eba489b5&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;shortName&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;VulDB&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dateUpdated&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2023-10-12T08:05:39.323Z&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;title&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Subscribe to Comments Plugin subscribe-to-comments.php cross site scripting&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;problemTypes&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;descriptions&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cweId&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-79&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;en&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CWE-79 Cross Site Scripting&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vendor&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;n/a&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;product&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Subscribe to Comments Plugin&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;versions&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.2&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.3&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.4&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.5&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.6&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0.7&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;status&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;affected&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;descriptions&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;en&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.8 is able to address this issue. The identifier of the patch is 9683bdf462fcac2f32b33be98f0b96497fbd1bb6. It is recommended to upgrade the affected component. The identifier VDB-222321 was assigned to this vulnerability.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;de&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Es wurde eine problematische Schwachstelle in Subscribe to Comments Plugin bis 2.0.7 für WordPress gefunden. Hiervon betroffen ist ein unbekannter Codeblock der Datei subscribe-to-comments.php. Dank der Manipulation mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Ein Aktualisieren auf die Version 2.0.8 vermag dieses Problem zu lösen. Der Patch wird als 9683bdf462fcac2f32b33be98f0b96497fbd1bb6 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;metrics&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cvssV3_1&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;3.1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;baseScore&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;3.5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vectorString&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;baseSeverity&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;LOW&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cvssV3_0&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;3.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;baseScore&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;3.5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vectorString&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;baseSeverity&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;LOW&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;cvssV2_0&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;baseScore&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vectorString&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AV:N/AC:L/Au:S/C:N/I:P/A:N&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;timeline&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;time&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2023-03-04T00:00:00.000Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;en&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Advisory disclosed&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;time&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2023-03-04T00:00:00.000Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;en&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE reserved&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;time&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2023-03-04T01:00:00.000Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;en&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;VulDB entry created&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;time&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2023-03-31T12:24:01.000Z&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;en&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;VulDB last update&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;credits&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;lang&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;en&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;value&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;VulDB GitHub Commit Analyzer&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;tool&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;references&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://vuldb.com/?id.222321&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vdb-entry&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;technical-description&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://vuldb.com/?ctiid.222321&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;signature&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;permissions-required&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://github.com/wp-plugins/subscribe-to-comments/commit/9683bdf462fcac2f32b33be98f0b96497fbd1bb6&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;patch&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://github.com/wp-plugins/subscribe-to-comments/releases/tag/2.0.8&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;patch&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;adp&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;providerMetadata&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;orgId&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;af854a3a-2127-422b-91ae-364da2661108&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;shortName&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;dateUpdated&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2024-08-07T20:57:41.047Z&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;title&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CVE Program Container&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;references&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://vuldb.com/?id.222321&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;vdb-entry&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;technical-description&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;x_transferred&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://vuldb.com/?ctiid.222321&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;signature&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;permissions-required&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;x_transferred&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://github.com/wp-plugins/subscribe-to-comments/commit/9683bdf462fcac2f32b33be98f0b96497fbd1bb6&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;patch&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;x_transferred&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://github.com/wp-plugins/subscribe-to-comments/releases/tag/2.0.8&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;patch&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;x_transferred&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="hextra-code-copy-btn-container hx:opacity-0 hx:transition hx:group-hover/code:opacity-100 hx:flex hx:gap-1 hx:absolute hx:m-[11px] hx:right-0 hx:top-0"&gt;
&lt;button
class="hextra-code-copy-btn hx:group/copybtn hx:cursor-pointer hx:transition-all hx:active:opacity-50 hx:bg-primary-700/5 hx:border hx:border-black/5 hx:text-gray-600 hx:hover:text-gray-900 hx:rounded-md hx:p-1.5 hx:dark:bg-primary-300/10 hx:dark:border-white/10 hx:dark:text-gray-400 hx:dark:hover:text-gray-50"
title="Copy code"
&gt;
&lt;div class="hextra-copy-icon hx:group-[.copied]/copybtn:hidden hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;div class="hextra-success-icon hx:hidden hx:group-[.copied]/copybtn:block hx:pointer-events-none hx:h-4 hx:w-4"&gt;&lt;/div&gt;
&lt;/button&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Added reverse mapping support for CWEs.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/84608bb4785b569497d661b673b1852ca15b60ca"target="_blank" rel="noopener"&gt;84608bb&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;CWEs are now stored in dedicated kvrocks sets for vulnerabilities added through the Vulnogram interface.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5d5204817f55b12e36d4e1c150e5d38c41b3d85d"target="_blank" rel="noopener"&gt;5d52048&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Improved loading mechanism for custom Jinja filters.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f14c2621371cffac8fb22536c484232be1551a04"target="_blank" rel="noopener"&gt;f14c262&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Numerous improvements to the vulnerability details page.&lt;/li&gt;
&lt;li&gt;Several enhancements to the OpenAPI documentation.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/07/vuln-detail-page.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/07/vuln-detail-page.png" alt="Various improvements to the vulnerability details page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Fixed creation and editing of notifications when the specified organization or product does not exist.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/141"target="_blank" rel="noopener"&gt;#141&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;POST /vulnerability&lt;/code&gt; endpoint now correctly sets vendor and product names in kvrocks for entries created via the Vulnogram web interface.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9cc2a5b29409e87a5b0fb17209096d8c992cf045"target="_blank" rel="noopener"&gt;9cc2a5b&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;CSAF feeders now correctly detect and process vulnerability updates.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/49c831a3c3db69fef00e00ac0a6b18641cbabaa0"target="_blank" rel="noopener"&gt;49c831a&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 To explore the full list of changes, visit the changelog on GitHub:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.13.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.13.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you very much to all the contributors and testers!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;br&gt;
Your feedback is always appreciated!&lt;/p&gt;
&lt;h2&gt;Follow Us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - June 2025</title><link>http://www.vulnerability-lookup.org/2025/07/07/vulnerability-report-june-2025/</link><pubDate>Mon, 07 Jul 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/07/07/vulnerability-report-june-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for June 2025, based on sightings collected from various sources, including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists, &lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;, and more. For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The final section focuses on exploitations observed through &lt;a href="https://www.shadowserver.org"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;&amp;rsquo;s honeypot network.&lt;/p&gt;
&lt;h2&gt;The Month at a Glance&lt;span class="hx:absolute hx:-mt-20" id="the-month-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#the-month-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The June 2025 report highlights a mix of long-standing and newly identified high-risk vulnerabilities. Notably, Citrix discloses a critical NetScaler ADC/Gateway flaw (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;), dubbed “CitrixBleed 2,” which can expose session tokens and bypass multi-factor authentication — echoing last year’s infamous CitrixBleed. Other urgent issues include a PayU India WordPress plugin vulnerability (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31022"target="_blank" rel="noopener"&gt;CVE-2025-31022&lt;/a&gt;) that allows full account takeover across thousands of sites, and a Python “tarfile” library bug (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4517"target="_blank" rel="noopener"&gt;CVE-2025-4517&lt;/a&gt;) that enables attackers to write files outside intended directories. Among the most sighted vulnerabilities are multiple Microsoft Windows 10 and Google Chrome flaws, as well as several Citrix ADC bugs, many rated “High” or “Critical.” Common web weaknesses like cross-site scripting and SQL injection (&lt;a href="https://vulnerability.circl.lu/cwes/CWE-79"target="_blank" rel="noopener"&gt;CWE-79&lt;/a&gt;, &lt;a href="https://vulnerability.circl.lu/cwes/CWE-89"target="_blank" rel="noopener"&gt;CWE-89&lt;/a&gt;) remain widespread, highlighting the ongoing need for strong patching hygiene. Some older vulnerabilities — such as the 2015 D-Link DIR-645 flaw and known Confluence or Cisco RCE bugs — also continue to see active exploitation. Organizations should prioritize remediation of these critical and actively targeted vulnerabilities, while reinforcing application security against injection and XSS attacks.&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.vulnerability-lookup.org/user-manual/ai/"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33053"target="_blank" rel="noopener"&gt;CVE-2025-33053&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows%2010%20Version%201809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-49113"target="_blank" rel="noopener"&gt;CVE-2025-49113&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube"target="_blank" rel="noopener"&gt;Roundcube&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Roundcube&amp;amp;product=Webmail"target="_blank" rel="noopener"&gt;Webmail&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5777"target="_blank" rel="noopener"&gt;CVE-2025-5777&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler"target="_blank" rel="noopener"&gt;NetScaler&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler&amp;amp;product=ADC"target="_blank" rel="noopener"&gt;ADC&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-5419"target="_blank" rel="noopener"&gt;CVE-2025-5419&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2783"target="_blank" rel="noopener"&gt;CVE-2025-2783&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6019"target="_blank" rel="noopener"&gt;CVE-2025-6019&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Red%20Hat"target="_blank" rel="noopener"&gt;Red Hat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Red%20Hat&amp;amp;product=Red%20Hat%20Enterprise%20Linux%2010"target="_blank" rel="noopener"&gt;Red Hat Enterprise Linux 10&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-33073"target="_blank" rel="noopener"&gt;CVE-2025-33073&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows%2010%20Version%201809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-6543"target="_blank" rel="noopener"&gt;CVE-2025-6543&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler"target="_blank" rel="noopener"&gt;NetScaler&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=NetScaler&amp;amp;product=ADC"target="_blank" rel="noopener"&gt;ADC&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link"target="_blank" rel="noopener"&gt;D-Link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;DIR-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ZyXEL"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;P660HN-T1A&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Evolution of sightings per week&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/vuln-evolutions.png" alt="Evolution of sightings per week" loading="lazy" /&gt;&lt;/p&gt;
&lt;h2&gt;Top 10 Weaknesses of the Month&lt;span class="hx:absolute hx:-mt-20" id="top-10-weaknesses-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-weaknesses-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CWE&lt;/th&gt;
&lt;th&gt;Number of vulnerabilities&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-79"target="_blank" rel="noopener"&gt;CWE-79&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;659&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-89"target="_blank" rel="noopener"&gt;CWE-89&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;411&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-74"target="_blank" rel="noopener"&gt;CWE-74&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;342&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-119"target="_blank" rel="noopener"&gt;CWE-119&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;190&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-862"target="_blank" rel="noopener"&gt;CWE-862&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;157&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-352"target="_blank" rel="noopener"&gt;CWE-352&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;157&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-120"target="_blank" rel="noopener"&gt;CWE-120&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;105&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-94"target="_blank" rel="noopener"&gt;CWE-94&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;94&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-22"target="_blank" rel="noopener"&gt;CWE-22&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;86&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/cwes/CWE-98"target="_blank" rel="noopener"&gt;CWE-98&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;74&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Insights from Contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/bundle/07234762-c7df-4dde-a778-fbc97a0c452a"target="_blank" rel="noopener"&gt;CitrixBleed 2&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
Citrix patched a critical vulnerability in its NetScaler ADC and NetScaler Gateway products that is already being compared to the infamous CitrixBleed flaw exploited by ransomware gangs and other cyber scum, although there haven&amp;rsquo;t been any reports of active exploitation. Yet.&lt;/p&gt;
&lt;p&gt;Security analyst Kevin Beaumont dubbed the vulnerability &amp;ldquo;CitrixBleed 2.&amp;rdquo; As The Register&amp;rsquo;s readers likely remember, that earlier flaw (&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-4966"target="_blank" rel="noopener"&gt;CVE-2023-4966&lt;/a&gt;) allowed attackers to access a device&amp;rsquo;s memory, find session tokens, and then use those to impersonate an authenticated user while bypassing multi-factor authentication — which is also possible with this new bug.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0002"target="_blank" rel="noopener"&gt;GCVE-1-2025-0002: Cl0p Ransomware Data Exfiltration Vulnerable to RCE Attacks&lt;/a&gt;&lt;/strong&gt;
A newly identified security vulnerability in the Cl0p ransomware group’s data exfiltration utility has exposed a critical remote code execution (RCE) flaw that security researchers and rival threat actors could potentially exploit.&lt;/p&gt;
&lt;p&gt;The vulnerability, designated as &lt;a href="https://vulnerability.circl.lu/vuln/GCVE-1-2025-0002"target="_blank" rel="noopener"&gt;GCVE-1-2025-0002&lt;/a&gt;, was published on July 1, 2025, and carries a high severity rating of 8.9 on the CVSS:4.0 scale.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/bundle/8d7e5f98-25d6-4fe3-87b8-d71838f2dafb"target="_blank" rel="noopener"&gt;Stuxnet-related CVEs&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-2568"target="_blank" rel="noopener"&gt;CVE-2010-2568&lt;/a&gt; MS10-046 Windows&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-2729"target="_blank" rel="noopener"&gt;CVE-2010-2729&lt;/a&gt; MS10-061 Windows&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2008-4250"target="_blank" rel="noopener"&gt;CVE-2008-4250&lt;/a&gt; MS08-067 Windows&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2010-2772"target="_blank" rel="noopener"&gt;CVE-2010-2772&lt;/a&gt; Not Available Siemens SIMATIC WinCC&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/comment/aaaf84c7-8007-4de5-b99f-ae9a91d6e26d"target="_blank" rel="noopener"&gt;CVE-2025-31022: More details about PayU wordpress extension&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
&amp;ldquo;This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might allow the malicious actor to gain admin access to the website.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/comment/85c55b2b-8a7a-4d34-89ec-52e38ed8903c"target="_blank" rel="noopener"&gt;CVE-2025-4517: Additional information&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
RISK : Multiple vulnerabilities affect the standard TarFile library for CPython. Currently, there is no indication that the vulnerability is actively exploited, but because it is a zero-day with a substantial install base, attackers can exploit it at any moment. An attacker could exploit flaws to bypass safety checks when extracting compressed files, allowing them to write files outside intended directories, create malicious links, or tamper with system files even when protections are supposedly enabled. Successful exploitation could lead to unauthorised access, data corruption, or malware installation, especially if your systems or third-party tools handle untrusted file uploads or archives RECOMMENDED ACTION: Patch Source: ccb.be&lt;/p&gt;
&lt;h2&gt;Continuous Exploitation&lt;span class="hx:absolute hx:-mt-20" id="continuous-exploitation"&gt;&lt;/span&gt;
&lt;a href="#continuous-exploitation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32433#sightings"target="_blank" rel="noopener"&gt;CVE-2025-32433&lt;/a&gt;&lt;/strong&gt; - erlang / otp&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051#sightings"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/strong&gt; - D-Link / DIR-645&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-26134#sightings"target="_blank" rel="noopener"&gt;CVE-2022-26134&lt;/a&gt;&lt;/strong&gt; - Atlassian / Confluence Data Center&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-1653#sightings"target="_blank" rel="noopener"&gt;CVE-2019-1653&lt;/a&gt;&lt;/strong&gt; - Cisco / Cisco Small Business RV Series Router Firmware&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Beyond CVEs: Mastering the Landscape with Vulnerability-Lookup</title><link>http://www.vulnerability-lookup.org/2025/06/25/beyond-cve-mastering-the-landscape-with-vulnerability-lookup/</link><pubDate>Wed, 25 Jun 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/06/25/beyond-cve-mastering-the-landscape-with-vulnerability-lookup/</guid><description>
&lt;p&gt;We had the pleasure of presenting at &lt;a href="https://www.first.org/"target="_blank" rel="noopener"&gt;FIRST.org 2025&lt;/a&gt;, showcasing the &lt;strong&gt;Vulnerability-Lookup&lt;/strong&gt; and &lt;a href="https://gcve.eu/"target="_blank" rel="noopener"&gt;GCVE.eu&lt;/a&gt; initiatives.&lt;/p&gt;
&lt;p&gt;Although CVEs are a cornerstone of vulnerability management, they often provide an incomplete view of the security landscape. &lt;strong&gt;Vulnerability-Lookup&lt;/strong&gt;, a new open-source project developed by CIRCL, addresses this limitation by offering a comprehensive and enriched vulnerability intelligence platform that goes beyond basic CVE data.&lt;/p&gt;
&lt;p&gt;The platform aggregates and correlates information from diverse sources, including exploit databases, vulnerability scanners, product advisories, and community contributions. This integration delivers a more complete picture of vulnerability threats. We demonstrate how this enhanced level of detail empowers security professionals to move beyond simple patch management and adopt proactive, actionable, risk-based strategies.&lt;/p&gt;
&lt;p&gt;📄 &lt;a href="http://www.vulnerability-lookup.org/files/events/2025/FIRST-CON-2025-Vulnerability-Lookup.pdf"&gt;Download the slides in PDF format&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter issues or have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time informationa about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.12.0 released</title><link>http://www.vulnerability-lookup.org/2025/06/20/vulnerability-lookup-2-12-0/</link><pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/06/20/vulnerability-lookup-2-12-0/</guid><description>
&lt;p&gt;We’re glad to announce the immediate availability of Vulnerability-Lookup version 2.12.0.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;CWE statistics&lt;span class="hx:absolute hx:-mt-20" id="cwe-statistics"&gt;&lt;/span&gt;
&lt;a href="#cwe-statistics" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Users can now access CWE occurrence statistics by year and optionally by month.&lt;br&gt;
The vulnerability detail page also displays the associated CWEs, with a direct link to the CWE detail page,
which includes potential mitigations. New Kvrocks indexes are used for the lookup.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/140"target="_blank" rel="noopener"&gt;#140&lt;/a&gt;) by &lt;a href="https://github.com/3LS3-1F"target="_blank" rel="noopener"&gt;Léa&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This update enhances accessibility by making it easier for everyone to explore trends in common weaknesses
over time directly through the web interface.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-overview.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-overview.png" alt="CWE Overview" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-Details-Mitigations.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-Details-Mitigations.png" alt="CWE Mitigations" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-Details-CAPECs.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-Details-CAPECs.png" alt="CWE CAPECs" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-Vuln-Page.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/CWE-Vuln-Page.png" alt="CWE on the vulnerability page" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Adding optional pull before update and optimized imports
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/164"target="_blank" rel="noopener"&gt;#164&lt;/a&gt;) by &lt;a href="https://github.com/P-T-I"target="_blank" rel="noopener"&gt;P-T-I&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;chg: [website] Provide a way to filter GNAs organization for unauthenticated users.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f537d56c522640033867a486bdc6900260fd6745"target="_blank" rel="noopener"&gt;f537d56&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;chg: [website] Display a message when the EPSS score is not yet available from FIRST.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1ef42b7c931c54a01e54c0ff5c38fb94de855d4b"target="_blank" rel="noopener"&gt;1ef42b7&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Various minor user interface improvements.&lt;/li&gt;
&lt;li&gt;Updated various dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 To see the full rundown of the changes, users can visit the changelog on GitHub:
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.12.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.12.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 A big thank you to &lt;a href="https://github.com/3LS3-1F"target="_blank" rel="noopener"&gt;Léa&lt;/a&gt;, and all contributors who helped make this happen!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter issues or have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.11.0 released</title><link>http://www.vulnerability-lookup.org/2025/06/13/vulnerability-lookup-2-11-0/</link><pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/06/13/vulnerability-lookup-2-11-0/</guid><description>
&lt;p&gt;We’re excited to announce the release of Vulnerability-Lookup 2.11.0 — and it comes with a major milestone for decentralized vulnerability publication!&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;GCVE-BCP-03 - Decentralized Publication Standard&lt;span class="hx:absolute hx:-mt-20" id="gcve-bcp-03---decentralized-publication-standard"&gt;&lt;/span&gt;
&lt;a href="#gcve-bcp-03---decentralized-publication-standard" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;a href="https://gcve.eu"target="_blank" rel="noopener"&gt;GCVE&lt;/a&gt; &lt;a href="https://gcve.eu/bcp/gcve-bcp-03"target="_blank" rel="noopener"&gt;BCP-03&lt;/a&gt; Decentralized Publication Standard has now been implemented for the first time.&lt;/p&gt;
&lt;p&gt;This standard enables &lt;a href="https://gcve.eu/glossary/#gna---gcve-numbering-authority"target="_blank" rel="noopener"&gt;GCVE Numbering Authority (GNA)&lt;/a&gt; organizations to publish their vulnerability information directly—without relying on a centralized system.&lt;/p&gt;
&lt;p&gt;As a first step, &lt;a href="http://www.vulnerability-lookup.org/2025/05/22/vulnerability-lookup-2-10-0/"&gt;version 2.10.0&lt;/a&gt; of Vulnerability-Lookup introduced support for maintaining a local copy of the GCVE registry.
With the latest release, it&amp;rsquo;s now possible to synchronize the list of local organizations in a Vulnerability-Lookup instance with this local GCVE registry.&lt;/p&gt;
&lt;p&gt;This new capability provides a simple way to maintain an up-to-date list of GNA organizations in any Vulnerability-Lookup deployment.&lt;/p&gt;
&lt;p&gt;Administrators can then choose which advisories, published by these GNA organizations, they want to import into their instance. This is possible thanks to a new feeder. (&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/151"target="_blank" rel="noopener"&gt;151&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security Advisories from the Local Vulnerability-Lookup Instance (gna-65535.private.circl.lu)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/local-vl-instance.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/local-vl-instance.png" alt="Security Advisories from the Local Vulnerability-Lookup Instance " loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This view displays advisories published on the current local instance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security Advisories from GNA-1 Retrieved in the Local Vulnerability-Lookup Instance (gna-65535.private.circl.lu)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/remote-vl-gna-1-circl.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/remote-vl-gna-1-circl.png" alt="Security Advisories from GNA-1 Retrieved in the Local Vulnerability-Lookup Instance" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This view shows advisories retrieved from a remote GNA instance (GNA-1) using the new feeder system.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security Advisories from GNA-1 Retrieved in the Local Vulnerability-Lookup Instance (vulnerability.circl.lu)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/gna-1-vl-instance.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/gna-1-vl-instance.png" alt="Security Advisories from GNA-1 Retrieved in the Local Vulnerability-Lookup Instance" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This screenshot displays the same advisory as in the previous example, but as seen on its originating instance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Dashboard&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/dashboard.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/dashboard.png" alt="Dashboard" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The dashboard where administrators manage the local GCVE registry.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Organization Management&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/dashboard-organizations-pull-gna.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/dashboard-organizations-pull-gna.png" alt="Organization Management" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This section allows the management of both GNA and non-GNA organizations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Editing an Organization&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/dashboard-edit-remote-organization.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/dashboard-edit-remote-organization.png" alt="Editing an Organization" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Editing details for a specific organization.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The distributed GCVE network&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/gcve-eu-network.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/gcve-eu-network.png" alt="The distributed GCVE network" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Added pagination in the API to the endpoint which list EMB3D objects.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commits/a669461cdfe4c671d860ede1b5ce3daa46c959aa"target="_blank" rel="noopener"&gt;a669461&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Vendor and Product management in vulnerability-lookup
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/105"target="_blank" rel="noopener"&gt;#105&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Improvements to the view of recent vulnerabilities.
The navigation menu is now automatically updated based on the list of GNAs the local instance is subscribed to.&lt;/li&gt;
&lt;li&gt;Various improvements to the admin dashboard.&lt;/li&gt;
&lt;li&gt;Various improvements to the documentation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Multiple comments share same UUID
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/158"target="_blank" rel="noopener"&gt;#158&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;GCVE data/feed is missing
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/155"target="_blank" rel="noopener"&gt;#155&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Dockerfile change by &lt;a href="https://github.com/P-T-I"target="_blank" rel="noopener"&gt;P-T-I&lt;/a&gt;
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/153"target="_blank" rel="noopener"&gt;#153&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixes to installation instructions by &lt;a href="https://github.com/jeroenh"target="_blank" rel="noopener"&gt;jeroenh&lt;/a&gt;
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/154"target="_blank" rel="noopener"&gt;#154&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;doc fix by &lt;a href="https://github.com/jeroenh"target="_blank" rel="noopener"&gt;jeroenh&lt;/a&gt;
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/156"target="_blank" rel="noopener"&gt;#156&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Small fixes on containers by &lt;a href="https://github.com/claudex"target="_blank" rel="noopener"&gt;claudex&lt;/a&gt;
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/157"target="_blank" rel="noopener"&gt;#157&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed a test in the disculosure.html template. The description of approved diclosures was never displayed.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commits/1ec3e55d5d3171f96a02443106243d9ca6bfc33f"target="_blank" rel="noopener"&gt;1ec3e55&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 To see the full rundown of the changes, users can visit the changelog on GitHub:
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.11.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.11.0&lt;/a&gt;
z&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter issues or have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time information about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - May 2025</title><link>http://www.vulnerability-lookup.org/2025/06/03/vulnerability-report-may-2025/</link><pubDate>Tue, 03 Jun 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/06/03/vulnerability-report-may-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for May 2025, based on sightings collected from various sources, including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists, &lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;, and more. For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The final section focuses on exploitations observed through &lt;a href="https://www.shadowserver.org"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;&amp;rsquo;s honeypot network.&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.vulnerability-lookup.org/user-manual/ai/"target="_blank" rel="noopener"&gt;VLAI Severity&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAP_SE"target="_blank" rel="noopener"&gt;SAP_SE&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAP_SE&amp;amp;product=SAP%20NetWeaver%20%28Visual%20Composer%20development%20server%29"target="_blank" rel="noopener"&gt;SAP NetWeaver (Visual Composer development server)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4427"target="_blank" rel="noopener"&gt;CVE-2025-4427&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint%20Manager%20Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-37899"target="_blank" rel="noopener"&gt;CVE-2025-37899&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4428"target="_blank" rel="noopener"&gt;CVE-2025-4428&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Ivanti&amp;amp;product=Endpoint%20Manager%20Mobile"target="_blank" rel="noopener"&gt;Endpoint Manager Mobile&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32756"target="_blank" rel="noopener"&gt;CVE-2025-32756&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Fortinet&amp;amp;product=FortiVoice"target="_blank" rel="noopener"&gt;FortiVoice&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4664"target="_blank" rel="noopener"&gt;CVE-2025-4664&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-20188"target="_blank" rel="noopener"&gt;CVE-2025-20188&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco%20IOS%20XE%20Software"target="_blank" rel="noopener"&gt;Cisco IOS XE Software&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ZyXEL"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;P660HN-T1A&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=D-Link"target="_blank" rel="noopener"&gt;D-Link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;DIR-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-38475"target="_blank" rel="noopener"&gt;CVE-2024-38475&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation&amp;amp;product=Apache%20HTTP%20Server"target="_blank" rel="noopener"&gt;Apache HTTP Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;td&gt;Critical&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Evolution for the top 5 vulnerabilities&lt;span class="hx:absolute hx:-mt-20" id="evolution-for-the-top-5-vulnerabilities"&gt;&lt;/span&gt;
&lt;a href="#evolution-for-the-top-5-vulnerabilities" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/06/sightings-evolution.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/06/sightings-evolution.png" alt="Evolution for the top 5 vulnerabilities" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt; - SAP / SAP NetWeaver (Visual Composer development server)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4427"target="_blank" rel="noopener"&gt;CVE-2025-4427&lt;/a&gt; - Ivanti / Endpoint Manager Mobile&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-37899"target="_blank" rel="noopener"&gt;CVE-2025-37899&lt;/a&gt; - Linux / Linux&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4428"target="_blank" rel="noopener"&gt;CVE-2025-4428&lt;/a&gt; - Ivanti / Endpoint Manager Mobile&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32756"target="_blank" rel="noopener"&gt;CVE-2025-32756&lt;/a&gt; - Fortinet / FortiVoice&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Insights from contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/comment/48d3bc1d-ce6b-4a0d-93f6-aec07945969d"target="_blank" rel="noopener"&gt;CVE-2025-22252: Authentication Vulnerability in FortiOS, FortiProxy, and FortiSwitchManager leads to Unauthenticated Admin Access&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
CVE-2025-22252 is a missing authentication for critical function vulnerability in devices configured to use a remote TACACS+ server for authentication configured to use ASCII authentication. It may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass, potentially resulting in complete system compromise, data theft and service disruption.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/comment/eff35358-2a58-408d-8c52-0b1143adc25c"target="_blank" rel="noopener"&gt;CVE-2025-30663: Additional information&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
In its security release of 13 May 2025, Zoom addressed two vulnerabilities that could be exploited for privilege escalation: • CVE-2025-30663, a time-of-check time-of-use race condition affecting some Zoom Workplace Apps. If successfully exploited, an authenticated user could conduct an escalation of privilege via local access. • CVE-2025-30664 is an improper neutralization of special elements flaw affecting some Zoom Workplace Apps. Successful exploitation could allow an authenticated user to conduct an escalation of privilege via local access.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/comment/da6e2e7d-cb96-4560-bf1a-27df4962776e"target="_blank" rel="noopener"&gt;CVE-2025-41229: More information&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
The vulnerabilities could be used by attackers to gain access to services and data. They can also be used to execute arbitrary commands and cause a denial of service. Confidentiality, integrity and availability are all impacted. The only solution is to upgrade immediately.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/comment/a79b754d-9252-4580-8912-42f39c854661"target="_blank" rel="noopener"&gt;2025-27920: Additional information&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
Microsoft discovered critical vulnerability CVE-2025-27920 affecting the messaging application Output Messenger. Microsoft additionally observed exploitation of the vulnerability since April 2024. According to Microsoft, the attacker needs to be authenticated, although the Output Messenger advisory indicates that privileges are not required to exploit the vulnerability. An attacker could upload malicious files into the server’s startup directory by exploiting this directory traversal vulnerability. This allows an attacker to gain indiscriminate access to the communications of every user, steal sensitive data and impersonate users, possibly leading to operational disruptions, unauthorized access to internal systems, and widespread credential compromise.&lt;/p&gt;
&lt;h2&gt;Continuous exploitation&lt;span class="hx:absolute hx:-mt-20" id="continuous-exploitation"&gt;&lt;/span&gt;
&lt;a href="#continuous-exploitation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-0656#sightings"target="_blank" rel="noopener"&gt;CVE-2023-0656&lt;/a&gt;&lt;/strong&gt; - SonicWall / SonicOS (&lt;strong&gt;not in CISA KEV&lt;/strong&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-26134#sightings"target="_blank" rel="noopener"&gt;CVE-2022-26134&lt;/a&gt;&lt;/strong&gt; - Atlassian / Confluence Data Center&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-1653#sightings"target="_blank" rel="noopener"&gt;CVE-2019-1653&lt;/a&gt;&lt;/strong&gt; - Cisco / Cisco Small Business RV Series Router Firmware&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Funding&lt;span class="hx:absolute hx:-mt-20" id="funding"&gt;&lt;/span&gt;
&lt;a href="#funding" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src="http://www.vulnerability-lookup.org/images/eu-funded.jpg" alt="eu_funded_en" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;The main objective of Federated European Team for Threat Analysis (&lt;a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/how-to-participate/org-details/999999999/project/101128030/program/43152860/details"target="_blank" rel="noopener"&gt;FETTA&lt;/a&gt;) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.&lt;br&gt;
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.&lt;/p&gt;
&lt;p&gt;The Computer Incident Response Center Luxembourg (&lt;a href="https://www.circl.lu"target="_blank" rel="noopener"&gt;CIRCL&lt;/a&gt;) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open sour
ce cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.10.0 released</title><link>http://www.vulnerability-lookup.org/2025/05/22/vulnerability-lookup-2-10-0/</link><pubDate>Thu, 22 May 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/05/22/vulnerability-lookup-2-10-0/</guid><description>
&lt;p&gt;We’re delighted to announce the release of Vulnerability-Lookup 2.10.0,
and it’s packed with exciting features!&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;AI-Powered Enrichment using our in-house AI models&lt;span class="hx:absolute hx:-mt-20" id="ai-powered-enrichment-using-our-in-house-ai-models"&gt;&lt;/span&gt;
&lt;a href="#ai-powered-enrichment-using-our-in-house-ai-models" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Vulnerability-Lookup now enhances vulnerability advisories using our in-house AI models.&lt;/p&gt;
&lt;p&gt;We recently worked on a new project, &lt;a href="https://github.com/vulnerability-lookup/ML-Gateway"target="_blank" rel="noopener"&gt;ML-Gateway&lt;/a&gt;,
a FastAPI service for serving NLP models. It loads one or more pre-trained NLP models during startup
and expose them through a clean, RESTful API for inference.
For example, it leverages the transformers library to load the
&lt;a href="https://huggingface.co/CIRCL/vulnerability-severity-classification-roberta-base"target="_blank" rel="noopener"&gt;CIRCL/vulnerability-severity-classification-roberta-base&lt;/a&gt;
model, which specializes in classifying vulnerability descriptions according to their severity level.
The server initializes this model once at startup, ensuring minimal latency during inference requests.&lt;/p&gt;
&lt;p&gt;The ultimate goal is to enrich vulnerability data descriptions through the application of a suite of NLP models, providing direct benefits to Vulnerability-Lookup and supporting other related projects
such as &lt;a href="https://ail-project.org"target="_blank" rel="noopener"&gt;AIL&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Think of it as a gateway to model-serving services, enabling us to integrate various AI models in the future without introducing new dependencies or added complexity to Vulnerability-Lookup.&lt;/p&gt;
&lt;p&gt;This release marks a significant milestone in our AI strategy.
We now have the full loop in place: from data gathering and vulnerability correlation to AI dataset generation,
model training with our own AI trainers, and finally, our new bridge that connects these models directly to Vulnerability-Lookup.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Example&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Concretely, for the user, the result of the severity classification model appears on the vulnerability description page in Vulnerability-Lookup, just after the CVSS information.
The goal is to provide a comparison point—and to offer a severity indicator when CVSS data is missing.
This result is composed of the level of the severity (from Low to Critical) and the confidence level (between 0 and 1).&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/05/example-ivanti.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/05/example-ivanti.png" alt="ML-Gateway" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-4427"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu/vuln/CVE-2025-4427&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Conceptual architecture of the ML-Gateway&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/05/ml-gateway.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/05/ml-gateway.png" alt="ML-Gateway" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Models generation workflow&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/05/models-generation.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/05/models-generation.png" alt="Models generation workflow" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;More information about &lt;a href="https://www.vulnerability-lookup.org/user-manual/ai/"target="_blank" rel="noopener"&gt;AI datasets and models&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Monitor Your Local GCVE Registry with Vulnerability-Lookup&lt;span class="hx:absolute hx:-mt-20" id="monitor-your-local-gcve-registry-with-vulnerability-lookup"&gt;&lt;/span&gt;
&lt;a href="#monitor-your-local-gcve-registry-with-vulnerability-lookup" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Thanks to the integration of the &lt;a href="https://github.com/gcve-eu/gcve"target="_blank" rel="noopener"&gt;GCVE client&lt;/a&gt;, administrators of a Vulnerability-Lookup
instance can now manage and monitor a local GCVE registry.&lt;/p&gt;
&lt;p&gt;GNAs are retrieved from &lt;a href="https://gcve.eu"target="_blank" rel="noopener"&gt;gcve.eu&lt;/a&gt;, and the integrity of the data is
automatically verified. In a future release, this will allow administrators of a
Vulnerability-Lookup instance to choose which GNA feeds to pull.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/05/gcve-eu-network.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/05/gcve-eu-network.png" alt="GCVE network" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/05/vl-dashboard-gcve.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/05/vl-dashboard-gcve.png" alt="Dashboard GCVE registry" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Send notifications to admins and users when new comments are added to a disclosure.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/58b6b60ccd45008448fee22358b40d79f82a17ab"target="_blank" rel="noopener"&gt;58b6b60&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Improved admin notification system for published comments.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2d2b9174f218f6bdcecb11a9f6021e8199195250"target="_blank" rel="noopener"&gt;2d2b917&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Added a new API endpoint to verify the integrity of the local GCVE registry.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a4416c6fcf1b3b5fbcda4e8f777e3e32925610bc"target="_blank" rel="noopener"&gt;a4416c6&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/27cd27cdb503271a0f4b48ee7d93a66b74b322da9217b50"target="_blank" rel="noopener"&gt;27cdb50&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/92c3c1b83be7f617f6904cc4d546f654c7554a02"target="_blank" rel="noopener"&gt;92c3c1b&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Introduced a new Flask/Click command to update the local GCVE registry in the background
using data from gcve.eu. This can also be triggered from the HML dashboard.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0a35027062f962ec705d33bc19cda03b3441fee3"target="_blank" rel="noopener"&gt;0a35027&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Queries the backend to retrieve the vendor/product information for hovered vulnerability
IDs in the charts and the table of the main public dashboard.
Related to &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/136"target="_blank" rel="noopener"&gt;#136&lt;/a&gt;
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/9f138a7a656bd430512c8ee4db96c75c2cf95181"target="_blank" rel="noopener"&gt;9f138a7&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Enhanced the vulnerability sightings correlation graph.
Related to &lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/136"target="_blank" rel="noopener"&gt;#136&lt;/a&gt;&lt;br&gt;
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ac17667364603a5c25e770000dd8d663ddf45910"target="_blank" rel="noopener"&gt;ac17667&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Various graphical improvements to the admin dashboard.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7c4e54929f85a65f1534cff0ee4a8699d1b703f1"target="_blank" rel="noopener"&gt;7c4e549&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Allowed &lt;code&gt;gna_id&lt;/code&gt; to be null for organizations.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/569bfa245f2e6d9b6f05376c5273c2ca921e102f"target="_blank" rel="noopener"&gt;569bfa2&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed typos in HTML templates.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e301a7f14d6ad3497e742aa02c8e625be6b32279"target="_blank" rel="noopener"&gt;e301a7f&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 To see the full rundown of the changes, users can visit the changelog on GitHub:
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.10.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.10.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 A big thank you to all our contributors — with a special welcome to &lt;a href="https://www.linkedin.com/in/l%c3%a9a-ulusan-379a3a239/"target="_blank" rel="noopener"&gt;Léa&lt;/a&gt;, our newest contributor!&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter issues or have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time informationa about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.9.0 released</title><link>http://www.vulnerability-lookup.org/2025/05/06/vulnerability-lookup-2-9-0/</link><pubDate>Tue, 06 May 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/05/06/vulnerability-lookup-2-9-0/</guid><description>
&lt;p&gt;We’re delighted to announce the release of Vulnerability-Lookup 2.9.0,
with new features, enhancements, and bug fixes.&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Adversarial Techniques from MITRE EMB3D&lt;span class="hx:absolute hx:-mt-20" id="adversarial-techniques-from-mitre-emb3d"&gt;&lt;/span&gt;
&lt;a href="#adversarial-techniques-from-mitre-emb3d" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The Adversarial Techniques from &lt;a href="https://emb3d.mitre.org"target="_blank" rel="noopener"&gt;MITRE EMB3D&lt;/a&gt;
are now integrated into Vulnerability-Lookup
as a new source and are correlated with existing security advisories.&lt;/p&gt;
&lt;p&gt;This feature was contributed by
&lt;a href="https://www.linkedin.com/in/piotr-kaminski-1336b012/"target="_blank" rel="noopener"&gt;Piotr Kaminski&lt;/a&gt; during the
last &lt;a href="https://hackathon.lu"target="_blank" rel="noopener"&gt;Hack.lu hackathon&lt;/a&gt;.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/129"target="_blank" rel="noopener"&gt;#129&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/05/2025-05-06-emb3d-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/05/2025-05-06-emb3d-1.png" alt="MITRE EMB3D" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Global CVE Allocation System (GCVE)&lt;span class="hx:absolute hx:-mt-20" id="global-cve-allocation-system-gcve"&gt;&lt;/span&gt;
&lt;a href="#global-cve-allocation-system-gcve" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;GCVE identifiers are now supported in HTML templates and URL parameters,&lt;br&gt;
thanks to the &lt;a href="https://pypi.org/project/gcve"target="_blank" rel="noopener"&gt;GCVE Python client&lt;/a&gt;.&lt;br&gt;
These identifiers can now be used when disclosing a new vulnerability as part of
the Coordinated Vulnerability Disclosure (CVD) process, in alignment with NIS 2 requirements.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/8bb3d84340ba25f0d09dcdbe5050f484e674d5fa"target="_blank" rel="noopener"&gt;8bb3d84&lt;/a&gt;,
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/58c394a86fa6d0581bac41aeb03f844678700705"target="_blank" rel="noopener"&gt;58c394a&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/05/2025-05-06-emb3d-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/05/2025-05-06-emb3d-2.png" alt="GCVE identifiers" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Trustworthy Level for Members&lt;span class="hx:absolute hx:-mt-20" id="trustworthy-level-for-members"&gt;&lt;/span&gt;
&lt;a href="#trustworthy-level-for-members" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Members of a Vulnerability-Lookup instance now have a dynamically calculated&lt;br&gt;
trustworthy level based on profile completeness and verification.&lt;br&gt;
Members affiliated with &lt;a href="https://www.first.org/"target="_blank" rel="noopener"&gt;FIRST.org&lt;/a&gt; or
&lt;a href="https://csirtsnetwork.eu"target="_blank" rel="noopener"&gt;European CSIRTs (CNW)&lt;/a&gt; are automatically&lt;br&gt;
trusted for operations that would otherwise require administrator approval&lt;br&gt;
(e.g., creating comments).&lt;/p&gt;
&lt;h2&gt;Changes&lt;span class="hx:absolute hx:-mt-20" id="changes"&gt;&lt;/span&gt;
&lt;a href="#changes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;New API endpoint for MITRE EMB3D.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/c0d6b44775b16f688a35a7d871f402fb64065cab"target="_blank" rel="noopener"&gt;c0d6b44&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Improved the vulnerability disclosure page.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ccfb6b1baffc73756ee692e5ac59249097939825"target="_blank" rel="noopener"&gt;ccfb6b1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Added page arguments to the &lt;code&gt;vulnerability/last&lt;/code&gt; endpoint.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ce75a7a55e8c8c2103fefbca3385930bf97ad6ec"target="_blank" rel="noopener"&gt;ce75a7a&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Notification emails now include a random signoff.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/119"target="_blank" rel="noopener"&gt;#119&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Various graphical enhancements.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/commit/0878a314b94ba21ce7c024e4563770e9a65e7761"target="_blank" rel="noopener"&gt;0878a31&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes&lt;span class="hx:absolute hx:-mt-20" id="fixes"&gt;&lt;/span&gt;
&lt;a href="#fixes" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;Fixed editing of notifications for Organization/Product.
(&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/124"target="_blank" rel="noopener"&gt;#124&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 To see the full rundown of the changes, users can visit the changelog on GitHub:
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.9.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.9.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you very much to all the contributors. Especially to
&lt;a href="https://www.linkedin.com/in/piotr-kaminski-1336b012/"target="_blank" rel="noopener"&gt;Piotr Kaminski&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter issues or have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time informationa about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - April 2025</title><link>http://www.vulnerability-lookup.org/2025/05/01/vulnerability-report-april-2025/</link><pubDate>Thu, 01 May 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/05/01/vulnerability-report-april-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for April 2025, based on sightings collected from various sources, including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists, &lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;, and more. For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The final section focuses on exploitations observed through &lt;a href="https://www.shadowserver.org"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;&amp;rsquo;s honeypot network.&lt;/p&gt;
&lt;h2&gt;Top 10 vulnerabilities of the month&lt;span class="hx:absolute hx:-mt-20" id="top-10-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-10-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22457"target="_blank" rel="noopener"&gt;CVE-2025-22457&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti&amp;amp;product=connect_secure"target="_blank" rel="noopener"&gt;Connect Secure&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;188&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32433"target="_blank" rel="noopener"&gt;CVE-2025-32433&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=erlang"target="_blank" rel="noopener"&gt;erlang&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=erlang&amp;amp;product=otp"target="_blank" rel="noopener"&gt;otp&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;119&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sap_se"target="_blank" rel="noopener"&gt;SAP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sap_se&amp;amp;product=sap&amp;#43;netweaver"target="_blank" rel="noopener"&gt;SAP NetWeaver&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;101&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31161"target="_blank" rel="noopener"&gt;CVE-2025-31161&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=crushftp"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=crushftp&amp;amp;product=crushftp"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;108&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29824"target="_blank" rel="noopener"&gt;CVE-2025-29824&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows&amp;#43;10&amp;#43;version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;85&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24054"target="_blank" rel="noopener"&gt;CVE-2025-24054&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows&amp;#43;10&amp;#43;version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;6.5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30406"target="_blank" rel="noopener"&gt;CVE-2025-30406&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=gladinet"target="_blank" rel="noopener"&gt;Gladinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=gladinet&amp;amp;product=centrestack"target="_blank" rel="noopener"&gt;CentreStack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;64&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24200"target="_blank" rel="noopener"&gt;CVE-2025-24200&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple&amp;amp;product=ipados"target="_blank" rel="noopener"&gt;iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;61&lt;/td&gt;
&lt;td&gt;6.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;p660hn-t1a_v1, p660hn-t1a_v2, 5200w-t&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;A scanner is available for CVE-2025-31324 (SAP):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/avishaifrad/f4e23a97156b1905a7ec8b962a9f2bc8"target="_blank" rel="noopener"&gt;https://gist.github.com/avishaifrad/f4e23a97156b1905a7ec8b962a9f2bc8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools"target="_blank" rel="noopener"&gt;https://github.com/Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can &lt;a href="https://vulnerability.circl.lu/user/notifications/create?vendor=SAP_SE&amp;amp;product=SAP&amp;#43;NetWeaver&amp;#43;%28Visual&amp;#43;Composer&amp;#43;development&amp;#43;server%29"target="_blank" rel="noopener"&gt;create a notification&lt;/a&gt; for this SAP product to get alerts about new activity.&lt;/p&gt;
&lt;p&gt;CVE-2017-18368 and CVE-2015-2051 are continuously exploited, with a recent increase in activity.&lt;/p&gt;
&lt;h2&gt;Evolution per week&lt;span class="hx:absolute hx:-mt-20" id="evolution-per-week"&gt;&lt;/span&gt;
&lt;a href="#evolution-per-week" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Week 14&lt;span class="hx:absolute hx:-mt-20" id="week-14"&gt;&lt;/span&gt;
&lt;a href="#week-14" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking"&gt;&lt;/span&gt;
&lt;a href="#ranking" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22457"target="_blank" rel="noopener"&gt;CVE-2025-22457&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti&amp;amp;product=connect_secure"target="_blank" rel="noopener"&gt;Connect Secure&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;100&lt;/td&gt;
&lt;td&gt;9.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31161"target="_blank" rel="noopener"&gt;CVE-2025-31161&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=crushftp"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=crushftp&amp;amp;product=crushftp"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;46&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30065"target="_blank" rel="noopener"&gt;CVE-2025-30065&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation&amp;amp;product=apache_parquet_java"target="_blank" rel="noopener"&gt;Apache Parquet Java&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;27&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation&amp;amp;product=apache&amp;#43;tomcat"target="_blank" rel="noopener"&gt;Apache Tomcat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1268"target="_blank" rel="noopener"&gt;CVE-2025-1268&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=canon&amp;#43;inc."target="_blank" rel="noopener"&gt;Canon Inc.&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=canon&amp;#43;inc.&amp;amp;product=generic&amp;#43;plus&amp;#43;pcl6&amp;#43;printer&amp;#43;driver"target="_blank" rel="noopener"&gt;Generic Plus PCL6 Printer Driver&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;td&gt;9.4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-20439"target="_blank" rel="noopener"&gt;CVE-2024-20439&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=cisco&amp;amp;product=cisco&amp;#43;smart&amp;#43;license&amp;#43;utility"target="_blank" rel="noopener"&gt;Cisco Smart License Utility&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;21&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1974"target="_blank" rel="noopener"&gt;CVE-2025-1974&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes"target="_blank" rel="noopener"&gt;kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes&amp;amp;product=ingress-nginx"target="_blank" rel="noopener"&gt;ingress-nginx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;20&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-26633"target="_blank" rel="noopener"&gt;CVE-2025-26633&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows&amp;#43;10&amp;#43;version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24201"target="_blank" rel="noopener"&gt;CVE-2025-24201&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple&amp;amp;product=ios_and_ipados"target="_blank" rel="noopener"&gt;iOS and iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;7.1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Week 15&lt;span class="hx:absolute hx:-mt-20" id="week-15"&gt;&lt;/span&gt;
&lt;a href="#week-15" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking-1"&gt;&lt;/span&gt;
&lt;a href="#ranking-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29824"target="_blank" rel="noopener"&gt;CVE-2025-29824&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows&amp;#43;10&amp;#43;version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;59&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22457"target="_blank" rel="noopener"&gt;CVE-2025-22457&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti&amp;amp;product=connect_secure"target="_blank" rel="noopener"&gt;Connect Secure&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;55&lt;/td&gt;
&lt;td&gt;9.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24200"target="_blank" rel="noopener"&gt;CVE-2025-24200&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple&amp;amp;product=ipados"target="_blank" rel="noopener"&gt;iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;46&lt;/td&gt;
&lt;td&gt;6.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-53197"target="_blank" rel="noopener"&gt;CVE-2024-53197&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=linux&amp;amp;product=linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;42&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31161"target="_blank" rel="noopener"&gt;CVE-2025-31161&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=crushftp"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=crushftp&amp;amp;product=crushftp"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;38&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-53150"target="_blank" rel="noopener"&gt;CVE-2024-53150&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=linux&amp;amp;product=linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;36&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-48887"target="_blank" rel="noopener"&gt;CVE-2024-48887&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=fortinet&amp;amp;product=fortiswitch"target="_blank" rel="noopener"&gt;FortiSwitch&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;31&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-0132"target="_blank" rel="noopener"&gt;CVE-2024-0132&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=nvidia"target="_blank" rel="noopener"&gt;NVIDIA&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=nvidia&amp;amp;product=container&amp;#43;toolkit"target="_blank" rel="noopener"&gt;Container Toolkit&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;24&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0108"target="_blank" rel="noopener"&gt;CVE-2025-0108&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=palo_alto_networks"target="_blank" rel="noopener"&gt;Palo Alto Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=palo&amp;#43;alto&amp;#43;networks&amp;amp;product=cloud&amp;#43;ngfw"target="_blank" rel="noopener"&gt;Cloud NGFW&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;Insights from contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/1b563420-7047-49bc-8488-2571aa82709c"target="_blank" rel="noopener"&gt;Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/d302d303-b999-46ae-9812-71067bf20469"target="_blank" rel="noopener"&gt;Is The Sofistication In The Room With Us? - X-Forwarded-For and Ivanti Connect Secure&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Week 16&lt;span class="hx:absolute hx:-mt-20" id="week-16"&gt;&lt;/span&gt;
&lt;a href="#week-16" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking-2"&gt;&lt;/span&gt;
&lt;a href="#ranking-2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32433"target="_blank" rel="noopener"&gt;CVE-2025-32433&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=erlang"target="_blank" rel="noopener"&gt;erlang&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=erlang&amp;amp;product=otp"target="_blank" rel="noopener"&gt;otp&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24054"target="_blank" rel="noopener"&gt;CVE-2025-24054&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows&amp;#43;10&amp;#43;version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;58&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31200"target="_blank" rel="noopener"&gt;CVE-2025-31200&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple&amp;amp;product=visionos"target="_blank" rel="noopener"&gt;visionOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;49&lt;/td&gt;
&lt;td&gt;7.5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30406"target="_blank" rel="noopener"&gt;CVE-2025-30406&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=gladinet"target="_blank" rel="noopener"&gt;Gladinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=gladinet&amp;amp;product=centrestack"target="_blank" rel="noopener"&gt;CentreStack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;44&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31201"target="_blank" rel="noopener"&gt;CVE-2025-31201&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple&amp;amp;product=visionos"target="_blank" rel="noopener"&gt;visionOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;42&lt;/td&gt;
&lt;td&gt;6.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24859"target="_blank" rel="noopener"&gt;CVE-2025-24859&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation&amp;amp;product=apache&amp;#43;roller"target="_blank" rel="noopener"&gt;Apache Roller&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;32&lt;/td&gt;
&lt;td&gt;2.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-20035"target="_blank" rel="noopener"&gt;CVE-2021-20035&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sonicwall"target="_blank" rel="noopener"&gt;SonicWall&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sonicwall&amp;amp;product=sma100"target="_blank" rel="noopener"&gt;SMA100&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;td&gt;6.5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29824"target="_blank" rel="noopener"&gt;CVE-2025-29824&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows&amp;#43;10&amp;#43;version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;24&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22457"target="_blank" rel="noopener"&gt;CVE-2025-22457&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti&amp;amp;product=connect_secure"target="_blank" rel="noopener"&gt;Connect Secure&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;23&lt;/td&gt;
&lt;td&gt;9.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-56406"target="_blank" rel="noopener"&gt;CVE-2024-56406&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=perl"target="_blank" rel="noopener"&gt;perl&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=perl&amp;amp;product=perl"target="_blank" rel="noopener"&gt;perl&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;8.6&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;Insights from contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors-1"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/00b15597-d2d6-413f-b3a1-38c62db1e6b0"target="_blank" rel="noopener"&gt;CVE-2025-24054, NTLM Exploit in the Wild - Checkpoint Research&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/9bbd91e2-309f-4b35-9b31-fc613b3101d9"target="_blank" rel="noopener"&gt;PHP Core Security Audit Results&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Week 17&lt;span class="hx:absolute hx:-mt-20" id="week-17"&gt;&lt;/span&gt;
&lt;a href="#week-17" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking-3"&gt;&lt;/span&gt;
&lt;a href="#ranking-3" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32433"target="_blank" rel="noopener"&gt;CVE-2025-32433&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=erlang"target="_blank" rel="noopener"&gt;erlang&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=erlang&amp;amp;product=otp"target="_blank" rel="noopener"&gt;otp&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;42&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31324"target="_blank" rel="noopener"&gt;CVE-2025-31324&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sap"target="_blank" rel="noopener"&gt;SAP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sap&amp;amp;product=sap_netweaver"target="_blank" rel="noopener"&gt;SAP NetWeaver&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;42&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-34028"target="_blank" rel="noopener"&gt;CVE-2025-34028&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=commvault"target="_blank" rel="noopener"&gt;Commvault&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=commvault&amp;amp;product=command&amp;#43;center&amp;#43;innovation&amp;#43;release"target="_blank" rel="noopener"&gt;Command Center Innovation Release&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;39&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0282"target="_blank" rel="noopener"&gt;CVE-2025-0282&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti"target="_blank" rel="noopener"&gt;Ivanti&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ivanti&amp;amp;product=connect_secure"target="_blank" rel="noopener"&gt;Connect Secure&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;24&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-32434"target="_blank" rel="noopener"&gt;CVE-2025-32434&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=pytorch"target="_blank" rel="noopener"&gt;pytorch&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=pytorch&amp;amp;product=pytorch"target="_blank" rel="noopener"&gt;pytorch&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;9.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24054"target="_blank" rel="noopener"&gt;CVE-2025-24054&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=microsoft&amp;amp;product=windows&amp;#43;10&amp;#43;version&amp;#43;1809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;6.5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-42013"target="_blank" rel="noopener"&gt;CVE-2021-42013&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache&amp;#43;software&amp;#43;foundation&amp;amp;product=apache_http_server"target="_blank" rel="noopener"&gt;Apache HTTP Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;p660hn-t1a_v1, p660hn-t1a_v2, 5200w-t&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1731"target="_blank" rel="noopener"&gt;CVE-2025-1731&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;Zyxel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=usg&amp;#43;flex&amp;#43;h&amp;#43;series&amp;#43;uos&amp;#43;firmware"target="_blank" rel="noopener"&gt;USG FLEX H series uOS firmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;Insights from contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors-2"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors-2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/avishaifrad/f4e23a97156b1905a7ec8b962a9f2bc8"target="_blank" rel="noopener"&gt;Check if SAP system is vulnerable to CVE-2025-31324&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/62e17ecb-0345-4b1c-b7d6-343410dd1084"target="_blank" rel="noopener"&gt;IBM WebSphere Application Server is vulnerable to server-side request forgery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/comment/a7120db2-1a20-4a03-849d-4688d5ea7992"target="_blank" rel="noopener"&gt;Path Traversal Vulnerability in Surveillance Software - Luxembourg and Belgium notified&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;CVEs with appearances from week 14 to 17&lt;span class="hx:absolute hx:-mt-20" id="cves-with-appearances-from-week-14-to-17"&gt;&lt;/span&gt;
&lt;a href="#cves-with-appearances-from-week-14-to-17" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Persistent ones (appear in at least 2 weeks):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2025-22457 – Week 14, 15, 16, 17&lt;/li&gt;
&lt;li&gt;CVE-2025-31161 – Week 14, 15, 17&lt;/li&gt;
&lt;li&gt;CVE-2025-29824 – Week 15, 16&lt;/li&gt;
&lt;li&gt;CVE-2025-24054 – Week 16, 17&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Appear only once&lt;span class="hx:absolute hx:-mt-20" id="appear-only-once"&gt;&lt;/span&gt;
&lt;a href="#appear-only-once" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Week 14 only:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2025-30065, CVE-2025-24813, CVE-2025-1268, CVE-2024-20439, CVE-2025-1974&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Week 15 only:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2025-24200, CVE-2024-53197, CVE-2024-53150&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Week 16 only:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;CVE-2025-32433, CVE-2025-31200
Week 17 only:&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;CVE-2025-31324, CVE-2025-0282, CVE-2025-1731&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Continuous exploitation&lt;span class="hx:absolute hx:-mt-20" id="continuous-exploitation"&gt;&lt;/span&gt;
&lt;a href="#continuous-exploitation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The sightings used for this analysis were mainly collected through
&lt;a href="https://www.shadowserver.org"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;&amp;rsquo;s honeypot network.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-1653"target="_blank" rel="noopener"&gt;CVE-2019-1653&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-12780"target="_blank" rel="noopener"&gt;CVE-2019-12780&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-42013"target="_blank" rel="noopener"&gt;CVE-2021-42013&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-6277"target="_blank" rel="noopener"&gt;CVE-2016-6277&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2016-10372"target="_blank" rel="noopener"&gt;CVE-2016-10372&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-44228"target="_blank" rel="noopener"&gt;CVE-2021-44228&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-9841"target="_blank" rel="noopener"&gt;CVE-2017-9841&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-17215"target="_blank" rel="noopener"&gt;CVE-2017-17215&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;This table highlights vulnerabilities that are consistently and recently exploited at a high rate.
Often found at network edges, such as routers, VPNs, and similar devices.&lt;/p&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability-Lookup 2.8.0 released</title><link>http://www.vulnerability-lookup.org/2025/04/10/vulnerability-lookup-2-8-0/</link><pubDate>Thu, 10 Apr 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/04/10/vulnerability-lookup-2-8-0/</guid><description>
&lt;p&gt;We’re pleased to announce the immediate availability of Vulnerability-Lookup version 2.8.0.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-user-profile.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-user-profile.png" alt="User profile with the new badge for vulnerability disclosure" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;What&amp;rsquo;s New&lt;span class="hx:absolute hx:-mt-20" id="whats-new"&gt;&lt;/span&gt;
&lt;a href="#whats-new" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Simplified Vulnerability Reporting (aligned with NIS 2 requirements)&lt;span class="hx:absolute hx:-mt-20" id="simplified-vulnerability-reporting-aligned-with-nis-2-requirements"&gt;&lt;/span&gt;
&lt;a href="#simplified-vulnerability-reporting-aligned-with-nis-2-requirements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Members of a Vulnerability-Lookup instance can now easily report vulnerabilities as
&lt;em&gt;preliminary advisories&lt;/em&gt; in the context of NIS 2. Operators can review these notifications
and, if deemed relevant, generate a security advisory directly from Vulnerability-Lookup.
The advisory will then be made publicly accessible, similar to those from other sources.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/114"target="_blank" rel="noopener"&gt;#114&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-admin-list-disclosures.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-admin-list-disclosures.png" alt="Administration - List of vulnerability disclosures" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-create-vulnerability-disclosure-1.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-create-vulnerability-disclosure-1.png" alt="Creation of a vulnerability disclosure - 1" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-create-vulnerability-disclosure-2.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-create-vulnerability-disclosure-2.png" alt="Creation of a vulnerability disclosure - 1" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-disclosure-comments.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-disclosure-comments.png" alt="Commenting on vulnerability disclosures" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-disclosure-date.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-disclosure-date.png" alt="Vulnerability disclosure release date" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;CodeClarity as a new Sighting source&lt;span class="hx:absolute hx:-mt-20" id="codeclarity-as-a-new-sighting-source"&gt;&lt;/span&gt;
&lt;a href="#codeclarity-as-a-new-sighting-source" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;During the &lt;a href="https://hackathon.lu"target="_blank" rel="noopener"&gt;Hack.lu hackathon&lt;/a&gt;, &lt;a href="https://github.com/CedricHerzog"target="_blank" rel="noopener"&gt;Cédric Herzog&lt;/a&gt;
worked on the new version of &lt;a href="https://www.codeclarity.io"target="_blank" rel="noopener"&gt;CodeClarity&lt;/a&gt;, which now supports pushing
analysis results as Sightings into Vulnerability-Lookup.&lt;/p&gt;
&lt;h3&gt;Dockerized version of Vulnerability-Lookup&lt;span class="hx:absolute hx:-mt-20" id="dockerized-version-of-vulnerability-lookup"&gt;&lt;/span&gt;
&lt;a href="#dockerized-version-of-vulnerability-lookup" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Thanks to &lt;a href="https://github.com/dawid-czarnecki"target="_blank" rel="noopener"&gt;Dawid Czarnecki&lt;/a&gt;, Vulnerability-Lookup now has a fully dockerized setup.
Kvrocks, Valkey, and PostgreSQL are each configured as separate containers.
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/pull/116"target="_blank" rel="noopener"&gt;#116&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Graphical improvements&lt;span class="hx:absolute hx:-mt-20" id="graphical-improvements"&gt;&lt;/span&gt;
&lt;a href="#graphical-improvements" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;We also refined several areas of the user interface to enhance usability and provide a smoother experience.
Thank you to &lt;a href="https://github.com/DavidCruciani"target="_blank" rel="noopener"&gt;David Cruciani&lt;/a&gt; !&lt;/p&gt;
&lt;h2&gt;Changelog&lt;span class="hx:absolute hx:-mt-20" id="changelog"&gt;&lt;/span&gt;
&lt;a href="#changelog" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;📂 To see the full rundown of the changes, users can visit the changelog on GitHub:
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.8.0"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.8.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🙏 Thank you very much to all the contributors. Especially to
&lt;a href="https://github.com/dawid-czarnecki"target="_blank" rel="noopener"&gt;Dawid Czarnecki&lt;/a&gt;
and &lt;a href="https://github.com/CedricHerzog"target="_blank" rel="noopener"&gt;Cédric Herzog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-security-advisory.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-10-security-advisory.png" alt="Security advisory based on a vulnerability disclosure" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you encounter issues or have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Follow us on Fediverse/Mastodon&lt;span class="hx:absolute hx:-mt-20" id="follow-us-on-fediversemastodon"&gt;&lt;/span&gt;
&lt;a href="#follow-us-on-fediversemastodon" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;You can follow us on Mastodon and get real time informationa about security advisories:&lt;br&gt;
&lt;a href="https://social.circl.lu/@vulnerability_lookup/"target="_blank" rel="noopener"&gt;https://social.circl.lu/@vulnerability_lookup/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Report - March 2025</title><link>http://www.vulnerability-lookup.org/2025/04/01/vulnerability-report-march-2025/</link><pubDate>Tue, 01 Apr 2025 00:00:00 +0000</pubDate><guid>http://www.vulnerability-lookup.org/2025/04/01/vulnerability-report-march-2025/</guid><description>
&lt;a
class="hextra-card hx:group hx:flex hx:flex-col hx:justify-start hx:overflow-hidden hx:rounded-lg hx:border hx:border-gray-200 hx:text-current hx:no-underline hx:dark:shadow-none hx:hover:shadow-gray-100 hx:dark:hover:shadow-none hx:shadow-gray-100 hx:active:shadow-sm hx:active:shadow-gray-200 hx:transition-all hx:duration-200 hx:hover:border-gray-300 hx:bg-transparent hx:shadow-xs hx:dark:border-neutral-800 hx:hover:bg-slate-50 hx:hover:shadow-md hx:dark:hover:border-neutral-700 hx:dark:hover:bg-neutral-900"href="http://www.vulnerability-lookup.org/tags/vulnerabilityreport/"
&gt;&lt;span class="hextra-card-icon hx:flex hx:font-semibold hx:items-start hx:gap-2 hx:p-4 hx:text-gray-700 hx:hover:text-gray-900 hx:dark:text-neutral-200 hx:dark:hover:text-neutral-50"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 24 24" stroke-width="2" stroke="currentColor" aria-hidden="true"&gt;&lt;path stroke-linecap="round" stroke-linejoin="round" d="M9 17v-2m3 2v-4m3 4v-6m2 10H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z"/&gt;&lt;/svg&gt;All vulnerability reports&lt;/span&gt;&lt;/a&gt;
&lt;h2&gt;Introduction&lt;span class="hx:absolute hx:-mt-20" id="introduction"&gt;&lt;/span&gt;
&lt;a href="#introduction" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;This vulnerability report has been generated using data aggregated on
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;Vulnerability-Lookup&lt;/a&gt;,
with contributions from the platform’s community.&lt;/p&gt;
&lt;p&gt;It highlights the most frequently mentioned vulnerability for March 2025, based on sightings collected from various sources, including &lt;a href="https://www.misp-project.org"target="_blank" rel="noopener"&gt;MISP&lt;/a&gt;, Exploit-DB, Bluesky, &lt;a href="https://joinmastodon.org"target="_blank" rel="noopener"&gt;Mastodon&lt;/a&gt;, GitHub Gists, &lt;a href="https://www.shadowserver.org/"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;, &lt;a href="https://github.com/projectdiscovery/nuclei"target="_blank" rel="noopener"&gt;Nuclei&lt;/a&gt;, and more. For further details, please visit &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The final section focuses on exploitations observed through &lt;a href="https://www.shadowserver.org"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;&amp;rsquo;s honeypot network.&lt;/p&gt;
&lt;h2&gt;March at a glance&lt;span class="hx:absolute hx:-mt-20" id="march-at-a-glance"&gt;&lt;/span&gt;
&lt;a href="#march-at-a-glance" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Sightings repartition per day&lt;span class="hx:absolute hx:-mt-20" id="sightings-repartition-per-day"&gt;&lt;/span&gt;
&lt;a href="#sightings-repartition-per-day" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-march-report-month-view.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-march-report-month-view.png" alt="Month at a glance" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Repartition of &lt;a href="https://www.vulnerability-lookup.org/user-manual/sightings/"target="_blank" rel="noopener"&gt;all type of sightings&lt;/a&gt; per day for the month of March.&lt;/p&gt;
&lt;h3&gt;Top 5 Vulnerabilities evolution&lt;span class="hx:absolute hx:-mt-20" id="top-5-vulnerabilities-evolution"&gt;&lt;/span&gt;
&lt;a href="#top-5-vulnerabilities-evolution" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-top-5-vulns-evolution.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-top-5-vulns-evolution.png" alt="Top 5 Vulnerabilities evolution" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For more detailed information, check out the Vulnerability-Lookup dashboard:&lt;br&gt;
&lt;a href="https://vulnerability.circl.lu"target="_blank" rel="noopener"&gt;https://vulnerability.circl.lu&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Top 15 vulnerabilities of the month&lt;span class="hx:absolute hx:-mt-20" id="top-15-vulnerabilities-of-the-month"&gt;&lt;/span&gt;
&lt;a href="#top-15-vulnerabilities-of-the-month" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-top-15-vulns.png"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-top-15-vulns.png" alt="Top 15 vulnerabilities of the month" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29927"target="_blank" rel="noopener"&gt;CVE-2025-29927&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/organization/b45e777e-9e1e-42cc-a7fb-4b1ad2f70a45"target="_blank" rel="noopener"&gt;vercel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/product/10a1964c-6295-4e11-b7f7-0b94a0e9ecab"target="_blank" rel="noopener"&gt;next.js&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;167&lt;/td&gt;
&lt;td&gt;9.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/organization/561aa5d5-8583-455d-b650-15f671751a47"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/product/83be5b68-8475-4ad9-8134-9fa499e23eea"target="_blank" rel="noopener"&gt;Apache Tomcat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;128&lt;/td&gt;
&lt;td&gt;9.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1974"target="_blank" rel="noopener"&gt;CVE-2025-1974&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes"target="_blank" rel="noopener"&gt;kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes&amp;amp;product=ingress-nginx"target="_blank" rel="noopener"&gt;ingress-nginx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;86&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-4577"target="_blank" rel="noopener"&gt;CVE-2024-4577&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=php"target="_blank" rel="noopener"&gt;PHP Group&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=php&amp;amp;product=php"target="_blank" rel="noopener"&gt;PHP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;83&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22224"target="_blank" rel="noopener"&gt;CVE-2025-22224&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=esxi"target="_blank" rel="noopener"&gt;ESXi&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;80&lt;/td&gt;
&lt;td&gt;9.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24201"target="_blank" rel="noopener"&gt;CVE-2025-24201&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apple&amp;amp;product=ios"target="_blank" rel="noopener"&gt;iOS and iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;79&lt;/td&gt;
&lt;td&gt;7.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2783"target="_blank" rel="noopener"&gt;CVE-2025-2783&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=google&amp;amp;product=chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;72&lt;/td&gt;
&lt;td&gt;8.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30066"target="_blank" rel="noopener"&gt;CVE-2025-30066&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=tj-actions"target="_blank" rel="noopener"&gt;tj-actions&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=tj-actions&amp;amp;product=changed-files"target="_blank" rel="noopener"&gt;changed-files&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;67&lt;/td&gt;
&lt;td&gt;8.6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;p660hn-t1a_v1, p660hn-t1a_v2, 5200w-t&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks"target="_blank" rel="noopener"&gt;dasannetworks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks&amp;amp;product=gpon_router"target="_blank" rel="noopener"&gt;gpon_router&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;54&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22225"target="_blank" rel="noopener"&gt;CVE-2025-22225&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=esxi"target="_blank" rel="noopener"&gt;ESXi&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;54&lt;/td&gt;
&lt;td&gt;8.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-23120"target="_blank" rel="noopener"&gt;CVE-2025-23120&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=veeam"target="_blank" rel="noopener"&gt;Veeam&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=veeam&amp;amp;product=backup-and-recovery"target="_blank" rel="noopener"&gt;Backup and Recovery&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;52&lt;/td&gt;
&lt;td&gt;9.9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22226"target="_blank" rel="noopener"&gt;CVE-2025-22226&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=esxi"target="_blank" rel="noopener"&gt;ESXi&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;48&lt;/td&gt;
&lt;td&gt;7.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27363"target="_blank" rel="noopener"&gt;CVE-2025-27363&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=freetype"target="_blank" rel="noopener"&gt;FreeType&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=freetype&amp;amp;product=freetype"target="_blank" rel="noopener"&gt;FreeType&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;47&lt;/td&gt;
&lt;td&gt;8.1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Evolution per week&lt;span class="hx:absolute hx:-mt-20" id="evolution-per-week"&gt;&lt;/span&gt;
&lt;a href="#evolution-per-week" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3&gt;Week 10&lt;span class="hx:absolute hx:-mt-20" id="week-10"&gt;&lt;/span&gt;
&lt;a href="#week-10" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking"&gt;&lt;/span&gt;
&lt;a href="#ranking" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22224"target="_blank" rel="noopener"&gt;CVE-2025-22224&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=esxi"target="_blank" rel="noopener"&gt;esxi&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;72&lt;/td&gt;
&lt;td&gt;9.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22225"target="_blank" rel="noopener"&gt;CVE-2025-22225&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=esxi"target="_blank" rel="noopener"&gt;esxi&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;50&lt;/td&gt;
&lt;td&gt;8.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22226"target="_blank" rel="noopener"&gt;CVE-2025-22226&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=ESXi"target="_blank" rel="noopener"&gt;ESXi&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;44&lt;/td&gt;
&lt;td&gt;7.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-50302"target="_blank" rel="noopener"&gt;CVE-2024-50302&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Linux&amp;amp;product=Linux"target="_blank" rel="noopener"&gt;Linux&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;39&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-8639"target="_blank" rel="noopener"&gt;CVE-2018-8639&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows%207"target="_blank" rel="noopener"&gt;Windows 7&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1316"target="_blank" rel="noopener"&gt;CVE-2025-1316&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Edimax"target="_blank" rel="noopener"&gt;Edimax&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Edimax&amp;amp;product=IC-7100%20IP%20Camera"target="_blank" rel="noopener"&gt;IC-7100 IP Camera&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;9.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-20118"target="_blank" rel="noopener"&gt;CVE-2023-20118&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco"target="_blank" rel="noopener"&gt;Cisco&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Cisco&amp;amp;product=Cisco%20Small%20Business%20RV%20Series%20Router%20Firmware"target="_blank" rel="noopener"&gt;Cisco Small Business RV Series Router Firmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;6.5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-43093"target="_blank" rel="noopener"&gt;CVE-2024-43093&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Android"target="_blank" rel="noopener"&gt;Android&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-4577"target="_blank" rel="noopener"&gt;CVE-2024-4577&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=PHP%20Group"target="_blank" rel="noopener"&gt;PHP Group&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=PHP%20Group&amp;amp;product=PHP"target="_blank" rel="noopener"&gt;PHP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2022-43769"target="_blank" rel="noopener"&gt;CVE-2022-43769&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Hitachi%20Vantara"target="_blank" rel="noopener"&gt;Hitachi Vantara&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Hitachi%20Vantara&amp;amp;product=Pentaho%20Business%20Analytics%20Server"target="_blank" rel="noopener"&gt;Pentaho Business Analytics Server&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ZyXEL"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ZyXEL&amp;amp;product=p660hn-t1a_v1,p660hn-t1a_v2,5200w-t"target="_blank" rel="noopener"&gt;p660hn-t1a_v1, p660hn-t1a_v2, 5200w-t&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;8.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-44228"target="_blank" rel="noopener"&gt;CVE-2021-44228&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation&amp;amp;product=Apache%20Log4j2"target="_blank" rel="noopener"&gt;Apache Log4j2&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2018-10562"target="_blank" rel="noopener"&gt;CVE-2018-10562&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks"target="_blank" rel="noopener"&gt;dasannetworks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dasannetworks&amp;amp;product=gpon_router"target="_blank" rel="noopener"&gt;gpon_router&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25012"target="_blank" rel="noopener"&gt;CVE-2025-25012&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Elastic"target="_blank" rel="noopener"&gt;Elastic&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Elastic&amp;amp;product=kibana"target="_blank" rel="noopener"&gt;Kibana&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;CVE-2025-25012 has been reserved and is pending publication.&lt;/p&gt;
&lt;h4&gt;Insights from contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/f5e26632-2e27-44d4-8620-cfc829f6488a"target="_blank" rel="noopener"&gt;VMSA-2025-0004: VMware ESXi, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/d41ef7ed-39b6-4408-a718-2c3bce5fc99e"target="_blank" rel="noopener"&gt;StopRansomware: Ghost (Cring) Ransomware | CISA&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Week 11&lt;span class="hx:absolute hx:-mt-20" id="week-11"&gt;&lt;/span&gt;
&lt;a href="#week-11" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking-1"&gt;&lt;/span&gt;
&lt;a href="#ranking-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24201"target="_blank" rel="noopener"&gt;CVE-2025-24201&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple"target="_blank" rel="noopener"&gt;Apple&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apple&amp;amp;product=iOS%20and%20iPadOS"target="_blank" rel="noopener"&gt;iOS and iPadOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;td&gt;7.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation&amp;amp;product=Apache%20Tomcat"target="_blank" rel="noopener"&gt;Apache Tomcat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;38&lt;/td&gt;
&lt;td&gt;9.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-4577"target="_blank" rel="noopener"&gt;CVE-2024-4577&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=PHP%20Group"target="_blank" rel="noopener"&gt;PHP Group&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=PHP%20Group&amp;amp;product=PHP"target="_blank" rel="noopener"&gt;PHP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;37&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27363"target="_blank" rel="noopener"&gt;CVE-2025-27363&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=FreeType"target="_blank" rel="noopener"&gt;FreeType&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=FreeType&amp;amp;product=FreeType"target="_blank" rel="noopener"&gt;FreeType&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;32&lt;/td&gt;
&lt;td&gt;8.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-8176"target="_blank" rel="noopener"&gt;CVE-2024-8176&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Red%20Hat"target="_blank" rel="noopener"&gt;Red Hat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Red%20Hat&amp;amp;product=Red%20Hat%20Enterprise%20Linux%206"target="_blank" rel="noopener"&gt;Red Hat Enterprise Linux 6&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;td&gt;7.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-1234"target="_blank" rel="noopener"&gt;CVE-2023-1234&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;td&gt;4.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-27636"target="_blank" rel="noopener"&gt;CVE-2025-27636&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation&amp;amp;product=Apache%20Camel"target="_blank" rel="noopener"&gt;Apache Camel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;6.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24983"target="_blank" rel="noopener"&gt;CVE-2025-24983&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows%2010%20Version%201507"target="_blank" rel="noopener"&gt;Windows 10 Version 1507&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;7.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25291"target="_blank" rel="noopener"&gt;CVE-2025-25291&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAML-Toolkits"target="_blank" rel="noopener"&gt;SAML-Toolkits&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAML-Toolkits&amp;amp;product=ruby-saml"target="_blank" rel="noopener"&gt;ruby-saml&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17&lt;/td&gt;
&lt;td&gt;9.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-25292"target="_blank" rel="noopener"&gt;CVE-2025-25292&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAML-Toolkits"target="_blank" rel="noopener"&gt;SAML-Toolkits&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=SAML-Toolkits&amp;amp;product=ruby-saml"target="_blank" rel="noopener"&gt;ruby-saml&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17&lt;/td&gt;
&lt;td&gt;9.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-21590"target="_blank" rel="noopener"&gt;CVE-2025-21590&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Juniper%20Networks"target="_blank" rel="noopener"&gt;Juniper Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Juniper%20Networks&amp;amp;product=Junos%20OS"target="_blank" rel="noopener"&gt;Junos OS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;6.7&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ZyXEL"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=ZyXEL&amp;amp;product=p660hn-t1a_v1%2C%20p660hn-t1a_v2%2C%205200w-t"target="_blank" rel="noopener"&gt;p660hn-t1a_v1, p660hn-t1a_v2, 5200w-t&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24993"target="_blank" rel="noopener"&gt;CVE-2025-24993&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows%2010%20Version%201809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2023-1389"target="_blank" rel="noopener"&gt;CVE-2023-1389&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=tp-link"target="_blank" rel="noopener"&gt;tp-link&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=tp-link&amp;amp;product=TP-Link%20Archer%20AX21%20%28AX1800%29"target="_blank" rel="noopener"&gt;TP-Link Archer AX21 (AX1800)&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;12&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;Insights from contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors-1"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors-1" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/2002296b-dd57-45e0-b127-feeaa53cc204"target="_blank" rel="noopener"&gt;Pre-authentication SQL injection to RCE in GLPI (CVE-2025-24799/CVE-2025-24801)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Week 12&lt;span class="hx:absolute hx:-mt-20" id="week-12"&gt;&lt;/span&gt;
&lt;a href="#week-12" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking-2"&gt;&lt;/span&gt;
&lt;a href="#ranking-2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29927"target="_blank" rel="noopener"&gt;CVE-2025-29927&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vercel"target="_blank" rel="noopener"&gt;vercel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vercel&amp;amp;product=next.js"target="_blank" rel="noopener"&gt;next.js&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;68&lt;/td&gt;
&lt;td&gt;9.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache_software_foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=apache_software_foundation&amp;amp;product=apache_tomcat"target="_blank" rel="noopener"&gt;Apache Tomcat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;66&lt;/td&gt;
&lt;td&gt;9.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-30066"target="_blank" rel="noopener"&gt;CVE-2025-30066&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=tj-actions"target="_blank" rel="noopener"&gt;tj-actions&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=tj-actions&amp;amp;product=changed-files"target="_blank" rel="noopener"&gt;changed-files&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;51&lt;/td&gt;
&lt;td&gt;8.6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-23120"target="_blank" rel="noopener"&gt;CVE-2025-23120&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=veeam"target="_blank" rel="noopener"&gt;Veeam&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=veeam&amp;amp;product=backup_and_recovery"target="_blank" rel="noopener"&gt;Backup and Recovery&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;48&lt;/td&gt;
&lt;td&gt;9.9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-27564"target="_blank" rel="noopener"&gt;CVE-2024-27564&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dirk1983"target="_blank" rel="noopener"&gt;dirk1983&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dirk1983&amp;amp;product=mm1.ltd_source_code"target="_blank" rel="noopener"&gt;mm1.ltd source code&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;27&lt;/td&gt;
&lt;td&gt;5.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-48248"target="_blank" rel="noopener"&gt;CVE-2024-48248&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;Backup &amp;amp; Replication Director&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;8.6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-54471"target="_blank" rel="noopener"&gt;CVE-2024-54471&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=nakivo"target="_blank" rel="noopener"&gt;NAKIVO&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;5.5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-9956"target="_blank" rel="noopener"&gt;CVE-2024-9956&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=google&amp;amp;product=chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24472"target="_blank" rel="noopener"&gt;CVE-2025-24472&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=fortinet"target="_blank" rel="noopener"&gt;Fortinet&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=fortinet&amp;amp;product=fortios"target="_blank" rel="noopener"&gt;FortiOS&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17&lt;/td&gt;
&lt;td&gt;8.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-4577"target="_blank" rel="noopener"&gt;CVE-2024-4577&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=php_group"target="_blank" rel="noopener"&gt;PHP Group&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=php_group&amp;amp;product=php"target="_blank" rel="noopener"&gt;PHP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;17&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2129"target="_blank" rel="noopener"&gt;CVE-2025-2129&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;Mage AI&lt;/td&gt;
&lt;td&gt;17&lt;/td&gt;
&lt;td&gt;6.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-0108"target="_blank" rel="noopener"&gt;CVE-2025-0108&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=palo_alto_networks"target="_blank" rel="noopener"&gt;Palo Alto Networks&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=palo_alto_networks&amp;amp;product=cloud_ngfw"target="_blank" rel="noopener"&gt;Cloud NGFW&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1316"target="_blank" rel="noopener"&gt;CVE-2025-1316&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=edimax"target="_blank" rel="noopener"&gt;Edimax&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=edimax&amp;amp;product=ic-7100_ip_camera"target="_blank" rel="noopener"&gt;IC-7100 IP Camera&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;9.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2017-18368"target="_blank" rel="noopener"&gt;CVE-2017-18368&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel"target="_blank" rel="noopener"&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=zyxel&amp;amp;product=p660hn-t1a_v1"target="_blank" rel="noopener"&gt;p660hn-t1a_v1, p660hn-t1a_v2, 5200w-t&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2015-2051"target="_blank" rel="noopener"&gt;CVE-2015-2051&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink"target="_blank" rel="noopener"&gt;dlink&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=dlink&amp;amp;product=dir-645"target="_blank" rel="noopener"&gt;dir-645&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Week 13&lt;span class="hx:absolute hx:-mt-20" id="week-13"&gt;&lt;/span&gt;
&lt;a href="#week-13" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h4&gt;Ranking&lt;span class="hx:absolute hx:-mt-20" id="ranking-3"&gt;&lt;/span&gt;
&lt;a href="#ranking-3" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-29927"target="_blank" rel="noopener"&gt;CVE-2025-29927&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vercel"target="_blank" rel="noopener"&gt;vercel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vercel&amp;amp;product=next.js"target="_blank" rel="noopener"&gt;next.js&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;98&lt;/td&gt;
&lt;td&gt;9.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1974"target="_blank" rel="noopener"&gt;CVE-2025-1974&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes"target="_blank" rel="noopener"&gt;kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes&amp;amp;product=ingress-nginx"target="_blank" rel="noopener"&gt;ingress-nginx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;81&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2783"target="_blank" rel="noopener"&gt;CVE-2025-2783&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google"target="_blank" rel="noopener"&gt;Google&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Google&amp;amp;product=Chrome"target="_blank" rel="noopener"&gt;Chrome&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;td&gt;8.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1098"target="_blank" rel="noopener"&gt;CVE-2025-1098&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes"target="_blank" rel="noopener"&gt;kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes&amp;amp;product=ingress-nginx"target="_blank" rel="noopener"&gt;ingress-nginx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2857"target="_blank" rel="noopener"&gt;CVE-2025-2857&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Mozilla"target="_blank" rel="noopener"&gt;Mozilla&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Mozilla&amp;amp;product=Firefox"target="_blank" rel="noopener"&gt;Firefox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;29&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24514"target="_blank" rel="noopener"&gt;CVE-2025-24514&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes"target="_blank" rel="noopener"&gt;kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes&amp;amp;product=ingress-nginx"target="_blank" rel="noopener"&gt;ingress-nginx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-1097"target="_blank" rel="noopener"&gt;CVE-2025-1097&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes"target="_blank" rel="noopener"&gt;kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes&amp;amp;product=ingress-nginx"target="_blank" rel="noopener"&gt;ingress-nginx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;28&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-22230"target="_blank" rel="noopener"&gt;CVE-2025-22230&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware"target="_blank" rel="noopener"&gt;vmware&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=vmware&amp;amp;product=VMware%20Tools"target="_blank" rel="noopener"&gt;VMware Tools&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;td&gt;7.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-2825"target="_blank" rel="noopener"&gt;CVE-2025-2825&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=CrushFTP"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=CrushFTP&amp;amp;product=CrushFTP"target="_blank" rel="noopener"&gt;CrushFTP&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;23&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24813"target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation"target="_blank" rel="noopener"&gt;Apache Software Foundation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Apache%20Software%20Foundation&amp;amp;product=Apache%20Tomcat"target="_blank" rel="noopener"&gt;Apache Tomcat&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;9.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-26633"target="_blank" rel="noopener"&gt;CVE-2025-26633&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft"target="_blank" rel="noopener"&gt;Microsoft&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=Microsoft&amp;amp;product=Windows%2010%20Version%201809"target="_blank" rel="noopener"&gt;Windows 10 Version 1809&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;7.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-31160"target="_blank" rel="noopener"&gt;CVE-2025-31160&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=atop%20project"target="_blank" rel="noopener"&gt;atop project&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=atop%20project&amp;amp;product=atop"target="_blank" rel="noopener"&gt;atop&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;2.9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2025-24513"target="_blank" rel="noopener"&gt;CVE-2025-24513&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes"target="_blank" rel="noopener"&gt;kubernetes&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=kubernetes&amp;amp;product=ingress-nginx"target="_blank" rel="noopener"&gt;ingress-nginx&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;td&gt;4.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-9874"target="_blank" rel="noopener"&gt;CVE-2019-9874&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sitecore"target="_blank" rel="noopener"&gt;sitecore&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sitecore&amp;amp;product=cms"target="_blank" rel="noopener"&gt;cms&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;td&gt;9.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2019-9875"target="_blank" rel="noopener"&gt;CVE-2019-9875&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sitecore"target="_blank" rel="noopener"&gt;sitecore&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://vulnerability.circl.lu/search?vendor=sitecore&amp;amp;product=cms"target="_blank" rel="noopener"&gt;cms&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;8.8&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;Insights from contributors&lt;span class="hx:absolute hx:-mt-20" id="insights-from-contributors-2"&gt;&lt;/span&gt;
&lt;a href="#insights-from-contributors-2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/84edafcd-42a7-4c30-96f8-87de8e73e1ab"target="_blank" rel="noopener"&gt;Ingress NGINX Controller for Kubernetes - Vulnerabilities fixed in controller-v1.12.1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/9a5e050a-4772-4f07-b3cb-81eae488ff62"target="_blank" rel="noopener"&gt;Kaspersky - Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Continuous exploitation&lt;span class="hx:absolute hx:-mt-20" id="continuous-exploitation"&gt;&lt;/span&gt;
&lt;a href="#continuous-exploitation" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The sightings used for this analysis were mainly collected through
&lt;a href="https://www.shadowserver.org"target="_blank" rel="noopener"&gt;The Shadowserver Foundation&lt;/a&gt;&amp;rsquo;s honeypot network.&lt;/p&gt;
&lt;h3&gt;CVE-2024-4577 - PHP Group / PHP&lt;span class="hx:absolute hx:-mt-20" id="cve-2024-4577---php-group--php"&gt;&lt;/span&gt;
&lt;a href="#cve-2024-4577---php-group--php" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2024-4577#sightings"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-continuous-sightings-CVE-2024-4577.png" alt="PHP Group / PHP" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Total of 180 sightings from 2024-06-12 (sighting type: &lt;code&gt;seen&lt;/code&gt; from MISP) to 2025-03-30 (sighting type: &lt;code&gt;exploited&lt;/code&gt; from The Shadowserver Foundation).&lt;/p&gt;
&lt;p&gt;Mentioned in the bundle &lt;a href="https://vulnerability.circl.lu/bundle/d29dbde5-754c-4ca2-8a8b-47f3b9e077f7"target="_blank" rel="noopener"&gt;People’s Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations&lt;/a&gt;
created on 2024-09-24.&lt;/p&gt;
&lt;p&gt;MISP related events:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;3714e52f-0f9a-5bbd-a430-7051c621dd44 (2025-03-25)&lt;/li&gt;
&lt;li&gt;a1e796df-2ad8-4c8d-8b69-737a004e72dd (2025-02-23)&lt;/li&gt;
&lt;li&gt;3c19819c-1dac-4ef2-bfed-be5efa7e0123 (2025-02-23)&lt;/li&gt;
&lt;li&gt;3c19819c-1dac-4ef2-bfed-be5efa7e0123 (first sighting, 2024-06-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;CVE-2021-44228 - Apache Software Foundation / Apache Log4j2&lt;span class="hx:absolute hx:-mt-20" id="cve-2021-44228---apache-software-foundation--apache-log4j2"&gt;&lt;/span&gt;
&lt;a href="#cve-2021-44228---apache-software-foundation--apache-log4j2" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;&lt;a href="https://vulnerability.circl.lu/vuln/CVE-2021-44228#sightings"target="_blank" rel="noopener"&gt;&lt;img src="http://www.vulnerability-lookup.org/images/news/2025/04/2025-04-01-continuous-sightings-CVE-2021-44228.png" alt="Apache Software Foundation / Apache Log4j2" loading="lazy" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Total of 198 sightings from 2021-12-12 (sighting type: &lt;code&gt;seen&lt;/code&gt; from Microsoft Blog) to 2025-03-30 (sighting type: &lt;code&gt;exploited&lt;/code&gt; from The Shadowserver Foundation).&lt;/p&gt;
&lt;p&gt;Mentioned in bundles:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/fdda4963-0aa7-4d15-8a8f-969db8f304ca"target="_blank" rel="noopener"&gt;Black Basta’s Leaked Chat Logs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulnerability.circl.lu/bundle/11268897-8798-4ec2-bcac-b23fe0715823"target="_blank" rel="noopener"&gt;Cyber Threat Overview 2024 from CERT-FR&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Thank you&lt;span class="hx:absolute hx:-mt-20" id="thank-you"&gt;&lt;/span&gt;
&lt;a href="#thank-you" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Thank you to all the contributors and our diverse sources!&lt;/p&gt;
&lt;p&gt;If you want to contribute to the next report, you can &lt;a href="https://vulnerability.circl.lu/user/signup"target="_blank" rel="noopener"&gt;create your account&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Feedback and Support&lt;span class="hx:absolute hx:-mt-20" id="feedback-and-support"&gt;&lt;/span&gt;
&lt;a href="#feedback-and-support" class="subheading-anchor" aria-label="Permalink for this section"&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!&lt;br&gt;
&lt;a href="https://github.com/vulnerability-lookup/vulnerability-lookup/issues/"target="_blank" rel="noopener"&gt;https://github.com/vulnerability-lookup/vulnerability-lookup/issues/&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>