In 2025, many CVEs were exploited, averaging a CVSS severity rating of 8.5, with two hitting the maximum of 10.0, highlighting their critical importance.
Most Exploited Vulnerabilities of 2025:
By infosecbulletin
/ Saturday , September 5 2026
Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
By infosecbulletin
/ Saturday , September 5 2026
India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
By infosecbulletin
/ Saturday , September 5 2026
Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
By infosecbulletin
/ Saturday , September 5 2026
Microsoft has launched Project Zenith, a new Windows 11 experience for developers. It is made for powerful PCs that can...
Read More
By infosecbulletin
/ Friday , September 4 2026
Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws....
Read More
By infosecbulletin
/ Friday , September 4 2026
An unnamed security expert known as "Nightmare Eclipse" shared a CrowdStrike Falcon zero-day exploit called "FalconFlank." This tool allows hackers...
Read More
By infosecbulletin
/ Friday , September 4 2026
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for not properly protecting the data...
Read More
By infosecbulletin
/ Friday , September 4 2026
The FBI’s New Orleans field office has opened an investigation into the suspected source of more than 153 million driver’s...
Read More
By infosecbulletin
/ Thursday , September 3 2026
Google has launched Gemini 3.8, its newest model for reasoning and coding. It includes a special version named Gemini 3.8...
Read More
By infosecbulletin
/ Wednesday , September 2 2026
SonicWall unveiled advisory SNWLID-2026-0016 on September 1, 2026. It states that two SMA1000 flaws are being actively exploited. The main...
Read More
CVE-2025-55182: React2Shell
CVE-2025-32433: Erlang/OTP SSH Zero-Day Crisis
CVE-2025-59287: Microsoft WSUS Deserialization Vulnerability
CVE-2025-62221: Windows Cloud Files Driver Zero-Day
CVE-2025-62215: Windows Kernel Race Condition Zero-Day
CVE-2025-48572 and CVE-2025-48633: Android Framework Zero-Days
CVE-2025-5777: CitrixBleed 2
CVE-2025-20333 and CVE-2025-20362: Cisco Firewall Exploitation Chain
CVE-2025-9242: WatchGuard Firebox Out-of-Bounds Catastrophe
CVE-2025-6218: WinRAR Path Traversal Exploitation
CVE-2025-48384: Git Arbitrary File Write Vulnerability
CVE-2025-12480: Gladinet Triofox Improper Access Control
CVE-2025-32463: Sudo Privilege Escalation via Chroot
CVE-2025-4664: Chrome Cross-Origin Data Leak
CVE-2025-10585: Chrome V8 Type Confusion Zero-Day
CVE-2025-5086: DELMIA Apriso Deserialization Catastrophe
CVE-2025-41244: VMware Privilege Escalation by State Actors
CVE-2025-53690: Sitecore Deserialization Attacks
# Bangladesh now 3rd largest global source of DDoS attacks in 2025 Q3
MITRE Unveils Top 25 Most Dangerous Software Weaknesses of 2025