Vulnerabilities added to KEV in January 2025
Added14
Ransomware-linked6
Vendors11
By vendor
3
2
1
1
1
1
1
1
1
1
Nearby months
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2025-24085 | Apple Multiple Products | 2025-01-29 | 17.5% | Unknown |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | 2025-01-24 | 23.4% | Known |
| CVE-2020-11023 | JQuery JQuery | 2025-01-23 | 84.8% | Unknown |
| CVE-2024-50603 | Aviatrix Controllers | 2025-01-16 | 98.5% | Unknown |
| CVE-2025-21335 | Microsoft Windows | 2025-01-14 | 1.3% | Unknown |
| CVE-2025-21334 | Microsoft Windows | 2025-01-14 | 1.5% | Unknown |
| CVE-2025-21333 | Microsoft Windows | 2025-01-14 | 9.9% | Unknown |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | 2025-01-14 | 94.1% | Known |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | 2025-01-13 | 13.7% | Unknown |
| CVE-2023-48365 | Qlik Sense | 2025-01-13 | 47.4% | Known |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | 2025-01-08 | 99.9% | Known |
| CVE-2024-55550 | Mitel MiCollab | 2025-01-07 | 38.1% | Known |
| CVE-2024-41713 | Mitel MiCollab | 2025-01-07 | 98.1% | Known |
| CVE-2020-2883 | Oracle WebLogic Server | 2025-01-07 | 94.9% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.