CVE-2025-24893: XWiki Platform Eval Injection Vulnerability
CVE-2025-24893 affects XWiki Platform and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-10-30.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
CVE-2025-24893 affects XWiki Platform and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-10-30.
CVE-2025-41244 affects Broadcom VMware Aria Operations and VMware Tools and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-10-30.
CVE-2025-11371 affects Gladinet CentreStack and Triofox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-04.
CVE-2025-48703 affects CWP Control Web Panel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-04.
CVE-2025-21042 affects Samsung Mobile Devices and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-10.
CVE-2025-9242 affects WatchGuard Firebox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-12.
CVE-2025-62215 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-12.
CVE-2025-12480 affects Gladinet Triofox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-12.
CVE-2025-64446 affects Fortinet FortiWeb and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-14.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.