In 2025, many CVEs were exploited, averaging a CVSS severity rating of 8.5, with two hitting the maximum of 10.0, highlighting their critical importance.
Most Exploited Vulnerabilities of 2025:
By infosecbulletin
/ Saturday , September 19 2026
Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
By infosecbulletin
/ Friday , September 18 2026
Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and one of three data-hosting zones in the...
Read More
By infosecbulletin
/ Friday , September 18 2026
A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
By infosecbulletin
/ Thursday , September 17 2026
Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
By infosecbulletin
/ Thursday , September 17 2026
GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
By infosecbulletin
/ Monday , September 14 2026
Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
By infosecbulletin
/ Saturday , September 12 2026
German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
By infosecbulletin
/ Friday , September 11 2026
GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
CVE-2025-55182: React2Shell
CVE-2025-32433: Erlang/OTP SSH Zero-Day Crisis
CVE-2025-59287: Microsoft WSUS Deserialization Vulnerability
CVE-2025-62221: Windows Cloud Files Driver Zero-Day
CVE-2025-62215: Windows Kernel Race Condition Zero-Day
CVE-2025-48572 and CVE-2025-48633: Android Framework Zero-Days
CVE-2025-5777: CitrixBleed 2
CVE-2025-20333 and CVE-2025-20362: Cisco Firewall Exploitation Chain
CVE-2025-9242: WatchGuard Firebox Out-of-Bounds Catastrophe
CVE-2025-6218: WinRAR Path Traversal Exploitation
CVE-2025-48384: Git Arbitrary File Write Vulnerability
CVE-2025-12480: Gladinet Triofox Improper Access Control
CVE-2025-32463: Sudo Privilege Escalation via Chroot
CVE-2025-4664: Chrome Cross-Origin Data Leak
CVE-2025-10585: Chrome V8 Type Confusion Zero-Day
CVE-2025-5086: DELMIA Apriso Deserialization Catastrophe
CVE-2025-41244: VMware Privilege Escalation by State Actors
CVE-2025-53690: Sitecore Deserialization Attacks
# Bangladesh now 3rd largest global source of DDoS attacks in 2025 Q3
MITRE Unveils Top 25 Most Dangerous Software Weaknesses of 2025