In 2025, many CVEs were exploited, averaging a CVSS severity rating of 8.5, with two hitting the maximum of 10.0, highlighting their critical importance.
Most Exploited Vulnerabilities of 2025:
By infosecbulletin
/ Wednesday , August 5 2026
Cybersecurity Researcher Jeremiah Fowler uncovered and reported to Express VPN a publicly exposed database that was neither password-protected nor encrypted....
Read More
By infosecbulletin
/ Tuesday , August 4 2026
Thousands of data centers are in danger because of a 22-year-old problem in Baseboard Management Controller (BMC) processors, says the...
Read More
By infosecbulletin
/ Tuesday , August 4 2026
In an important move to boost the country's cybersecurity, Bangladesh started the Cyber Incident Reporting System (CIRS) and the National...
Read More
By infosecbulletin
/ Tuesday , August 4 2026
Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
By infosecbulletin
/ Tuesday , August 4 2026
TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
By infosecbulletin
/ Monday , August 3 2026
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
By infosecbulletin
/ Saturday , August 1 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
By infosecbulletin
/ Friday , July 31 2026
A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
By infosecbulletin
/ Friday , July 31 2026
Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
By infosecbulletin
/ Thursday , July 30 2026
NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
CVE-2025-55182: React2Shell
CVE-2025-32433: Erlang/OTP SSH Zero-Day Crisis
CVE-2025-59287: Microsoft WSUS Deserialization Vulnerability
CVE-2025-62221: Windows Cloud Files Driver Zero-Day
CVE-2025-62215: Windows Kernel Race Condition Zero-Day
CVE-2025-48572 and CVE-2025-48633: Android Framework Zero-Days
CVE-2025-5777: CitrixBleed 2
CVE-2025-20333 and CVE-2025-20362: Cisco Firewall Exploitation Chain
CVE-2025-9242: WatchGuard Firebox Out-of-Bounds Catastrophe
CVE-2025-6218: WinRAR Path Traversal Exploitation
CVE-2025-48384: Git Arbitrary File Write Vulnerability
CVE-2025-12480: Gladinet Triofox Improper Access Control
CVE-2025-32463: Sudo Privilege Escalation via Chroot
CVE-2025-4664: Chrome Cross-Origin Data Leak
CVE-2025-10585: Chrome V8 Type Confusion Zero-Day
CVE-2025-5086: DELMIA Apriso Deserialization Catastrophe
CVE-2025-41244: VMware Privilege Escalation by State Actors
CVE-2025-53690: Sitecore Deserialization Attacks
# Bangladesh now 3rd largest global source of DDoS attacks in 2025 Q3
MITRE Unveils Top 25 Most Dangerous Software Weaknesses of 2025