| CVE-2024-53704 | SonicWall SonicOS SSLVPN Improper Authentication | critical | 5 | 1 | 2 | 0 |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy Authentication Bypass | critical | 8 | 2 | 7 | 0 |
| CVE-2024-57727 | SimpleHelp Path Traversal | high | 5 | 2 | 5 | 0 |
| CVE-2025-0108 | Palo Alto Networks PAN-OS Authentication Bypass | high | 12 | 2 | 0 | 1 |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | critical | 12 | 8 | 1 | 0 |
| CVE-2025-0283 | Ivanti Connect Secure, Policy Secure, and Neurons Stack-Based Buffer Overflow | high | 0 | 3 | 0 | 0 |
| CVE-2025-0994 | Trimble Cityworks Deserialization | high | 0 | 3 | 0 | 0 |
| CVE-2025-3248 | Langflow Missing Authentication | critical | 35 | 1 | 0 | 1 |
| CVE-2025-3928 | Commvault Web Server Unspecified Vulnerability | high | 0 | 3 | 0 | 0 |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass | high | 8 | 4 | 0 | 0 |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection | high | 9 | 4 | 0 | 0 |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | critical | 26 | 4 | 1 | 0 |
| CVE-2025-6218 | RARLAB WinRAR Path Traversal Vulnerability | high | 10 | 5 | 0 | 0 |
| CVE-2025-6264 | Rapid7 Velociraptor Incorrect Default Permissions | medium | 2 | 1 | 2 | 0 |
| CVE-2025-7771 | ThrottleStop.sys Driver Exposed IOCTL with Insufficient Access Control | high | 6 | 1 | 4 | 0 |
| CVE-2025-8088 | RARLAB WinRAR Path Traversal | high | 21 | 8 | 1 | 1 |
| CVE-2025-10035 | Fortra GoAnywhere MFT Deserialization of Untrusted Data | critical | 5 | 2 | 2 | 0 |
| CVE-2025-20363 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Heap-Based Buffer Overflow | critical | 3 | 2 | 0 | 0 |
| CVE-2025-22224 | VMware ESXi and Workstation TOCTOU Race Condition | high | 0 | 1 | 3 | 0 |
| CVE-2025-22225 | VMware ESXi Arbitrary Write | high | 0 | 1 | 2 | 0 |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion Information Disclosure | medium | 0 | 1 | 2 | 0 |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | critical | 10 | 4 | 1 | 0 |
| CVE-2025-23006 | SonicWall SMA1000 Appliances Deserialization | critical | 1 | 1 | 1 | 0 |
| CVE-2025-24016 | Wazuh Server Deserialization | critical | 13 | 1 | 0 | 2 |
| CVE-2025-24071 | Microsoft Windows Exposure of Sensitive Information | medium | 26 | 1 | 0 | 0 |
| CVE-2025-24472 | Fortinet FortiOS and FortiProxy Authentication Bypass | high | 0 | 2 | 2 | 0 |
| CVE-2025-24813 | Apache Tomcat Path Equivalence Vulnerability | critical | 47 | 1 | 0 | 0 |
| CVE-2025-24893 | XWiki Platform Eval Injection | critical | 48 | 1 | 0 | 2 |
| CVE-2025-25257 | Fortinet FortiWeb SQL Injection | critical | 18 | 2 | 0 | 0 |
| CVE-2025-26633 | Microsoft Windows Management Console (MMC) Improper Neutralization | high | 5 | 2 | 2 | 0 |
| CVE-2025-29824 | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free | high | 11 | 2 | 3 | 0 |
| CVE-2025-29927 | Vercel Next.js Improper Authorization | critical | 82 | 1 | 0 | 0 |
| CVE-2025-31161 | CrushFTP Authentication Bypass | critical | 23 | 1 | 1 | 0 |
| CVE-2025-31324 | SAP NetWeaver Unrestricted File Upload | critical | 22 | 9 | 4 | 0 |
| CVE-2025-32433 | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function | critical | 39 | 1 | 0 | 0 |
| CVE-2025-32463 | Sudo Inclusion of Functionality from Untrusted Control Sphere | high | 67 | 1 | 0 | 0 |
| CVE-2025-33053 | Microsoft Windows External Control of File Name or Path | high | 10 | 3 | 0 | 0 |
| CVE-2025-34043 | Vacron Network Video Recorder (NVR) Remote Command Injection | critical | 2 | 1 | 0 | 3 |
| CVE-2025-48384 | Git Link Following Vulnerability | high | 27 | 2 | 0 | 0 |
| CVE-2025-49113 | Roundcube Webmail Deserialization | high | 24 | 2 | 0 | 0 |
| CVE-2025-49704 | Microsoft SharePoint Code Injection | high | 11 | 6 | 4 | 0 |
| CVE-2025-49706 | Microsoft SharePoint Improper Authentication | medium | 14 | 6 | 4 | 0 |
| CVE-2025-53770 | Microsoft SharePoint Deserialization | critical | 36 | 10 | 6 | 0 |
| CVE-2025-53771 | Microsoft SharePoint Improper Authentication | medium | 8 | 7 | 4 | 0 |
| CVE-2025-55182 | Meta React Server Components RCE (React2Shell) | critical | 236 | 11 | 2 | 4 |
| CVE-2025-59287 | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data | critical | 22 | 3 | 1 | 0 |
| CVE-2025-61882 | Oracle E-Business Suite Unspecified Vulnerability | critical | 12 | 4 | 2 | 0 |
| CVE-2025-61884 | Oracle E-Business Suite Server-Side Request Forgery | high | 4 | 1 | 2 | 0 |
| CVE-2025-61932 | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel | critical | 1 | 3 | 0 | 0 |
| CVE-2025-64446 | Fortinet FortiWeb Path Traversal | critical | 24 | 1 | 0 | 0 |