Vulnerabilities added to KEV in November 2025
Added11
Ransomware-linked0
Vendors9
By vendor
2
2
1
1
1
1
1
1
1
Nearby months
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2021-26829 | OpenPLC ScadaBR | 2025-11-28 | 48.0% | Unknown |
| CVE-2025-61757 | Oracle Fusion Middleware | 2025-11-21 | 88.6% | Unknown |
| CVE-2025-13223 | Google Chromium V8 | 2025-11-19 | 5.0% | Unknown |
| CVE-2025-58034 | Fortinet FortiWeb | 2025-11-18 | 55.5% | Unknown |
| CVE-2025-64446 | Fortinet FortiWeb | 2025-11-14 | 91.8% | Unknown |
| CVE-2025-9242 | WatchGuard Firebox | 2025-11-12 | 91.3% | Unknown |
| CVE-2025-62215 | Microsoft Windows | 2025-11-12 | 5.9% | Unknown |
| CVE-2025-12480 | Gladinet Triofox | 2025-11-12 | 95.4% | Unknown |
| CVE-2025-21042 | Samsung Mobile Devices | 2025-11-10 | 33.1% | Unknown |
| CVE-2025-48703 | CWP Control Web Panel | 2025-11-04 | 99.6% | Unknown |
| CVE-2025-11371 | Gladinet CentreStack and Triofox | 2025-11-04 | 92.1% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.