Vulnerability Report - February 2025

Vulnerability Report - February 2025

March 1, 2025

 #VulnerabilityReport#Report

All vulnerability reports

Introduction

This vulnerability report has been generated using data aggregated on Vulnerability-Lookup, with contributions from the platform’s community.

It highlights the most frequently mentioned vulnerability for February 2025, based on sightings collected from various sources, including MISP, Exploit-DB, Bluesky, Mastodon, GitHub Gists, The Shadowserver Foundation, Nuclei, and more. For further details, please visit this page.

The final section focuses on exploitations observed through The Shadowserver Foundation’s honeypot network.

February at a glance

Sightings repartition per day

Month at a glance

Repartition of all type of sightings per day for the month of January.

For more detailed information, check out the Vulnerability-Lookup dashboard:
https://vulnerability.circl.lu

Top 15 vulnerabilities of the month

The podium belongs to Ivanti, Fortinet, and Microsoft.

VulnerabilityVendorProductSeverity
CVE-2025-0282IvantiConnect Secure9.0
CVE-2024-55591FortinetFortiOS9.8
CVE-2024-49113MicrosoftWindows 10 Version 18097.5
CVE-2015-2051D-LinkDIR-6459.8
CVE-2017-18368ZyXELp660hn-t1a_v19.8
CVE-2025-0283IvantiConnect Secure7.0
CVE-2024-7344RadixSmartRecovery
CVE-2017-17215Huawei Technologies Co., Ltd.HG532
CVE-2018-10562dasannetworksgpon_router9.8
CVE-2024-50603AviatrixController10.0
CVE-2025-23006SonicWallSMA1000
CVE-2014-8361realtekrealtek_sdk9.8
CVE-2016-10372eird1000_modem9.8
CVE-2016-6277netgeard62208.8
CVE-2017-9841phpunit_projectphpunit9.8

Evolution per week

Week 6

Ranking

VulnerabilityCountVendorProduct
CVE-2024-5310461LinuxLinux
CVE-2025-0411547-Zip7-Zip
CVE-2024-2141325MicrosoftMicrosoft Office 2019
CVE-2025-099424TrimbleCityworks
CVE-2024-5616121AMDAMD EPYC™ 7001 Series
CVE-2025-2311420VeeamBackup for AWS
CVE-2025-2012418CiscoCisco Identity Services Engine Software
CVE-2024-4089115ZyxelVMG4325-B10A firmware
CVE-2025-2012515CiscoCisco Identity Services Engine Software
CVE-2017-1836814ZyXELP660HN-T1

Insights from contributors

Week 7

Ranking

VulnerabilityCountVendorProduct
CVE-2025-2420092AppleiPadOS
CVE-2025-010883Palo Alto NetworksCloud NGFW
CVE-2025-109457PostgreSQL
CVE-2025-2139135MicrosoftWindows 10 Version 1809
CVE-2025-2141829MicrosoftWindows 10 Version 1809
CVE-2024-5370427SonicWallSonicOS
CVE-2024-1235626BeyondTrustRemote Support
CVE-2024-1279722OpenSSLOpenSSL
CVE-2024-947420Palo Alto NetworksCloud NGFW
CVE-2023-4910316ownCloudownCloud

Insights from contributors

Week 8

Ranking

VulnerabilityCountVendorProduct
CVE-2025-010856Palo Alto NetworksCloud NGFW
CVE-2025-2646540Red HatRed Hat Enterprise Linux 6
CVE-2025-2646635OpenSSHOpenSSH
CVE-2025-2679330HirschEnterphone MESH
CVE-2025-011124Palo Alto NetworksCloud NGFW
CVE-2025-109424PostgreSQLPostgreSQL
CVE-2018-017120CiscoCisco IOS and IOS XE
CVE-2025-2498920MicrosoftMicrosoft Power Pages
CVE-2024-5370420SonicWallSonicOS
CVE-2025-2633920Q-FreeMaxTime

Insights from contributors

Week 9

Ranking

VulnerabilityCountVendorProduct
CVE-2017-306620AdobeAdobe ColdFusion
CVE-2024-2095320Oracle CorporationAgile PLM Framework
CVE-2025-2736419MITRECaldera
CVE-2024-4903513MicrosoftMicrosoft Partner Center
CVE-2023-2252712AtlassianConfluence Data Center
CVE-2023-3419211ZimbraZimbra ZCS v.8.8.15
CVE-2025-2005110MattermostMattermost
CVE-2023-201989CiscoCisco IOS XE Software
CVE-2024-482489NAKIVONAKIVO Backup and Replication Solution
CVE-2015-20518D-LinkDIR-645

Insights from contributors

Continuous exploitation

The sightings used for this analysis were mainly collected through The Shadowserver Foundation’s honeypot network.

Black Basta’s Leaked Chat Logs

On February 11, 2025, a significant leak exposed BLACKBASTA’s internal Matrix chat logs.

A bundle on Vulnerability-Lookup is tracking the observations we’ve detected related to Black Basta’s leaked chat logs. You will find all the impacted products, such as Zimbra, Microsoft Exchange Server, JetBrains, and PAN-OS.

As you can see, there are plenty of sighting correlations from Shadowserver and from MISP, with continuous exploitations.

CVE-2017-11882 (Microsoft Office) was detected in MISP seven years ago (MISP/5a17d980-5438-4503-ba89-693b0a950b0c). Additionally, recent exploitations have been observed for other CVEs. Various Nuclei templates are available for this set of vulnerabilities.

You can read an interesting comment with more details: Update on SVR Cyber Operations and Vulnerability Exploitation.

CVE-2016-6277 - Netgear

Exploitations Netgear

Thank you

Thank you to all the contributors and our diverse sources!

If you want to contribute to the next report, you can create your account.