Vulnerability Report - March 2025

Vulnerability Report - March 2025

April 1, 2025

 #VulnerabilityReport#Report

All vulnerability reports

Introduction

This vulnerability report has been generated using data aggregated on Vulnerability-Lookup, with contributions from the platform’s community.

It highlights the most frequently mentioned vulnerability for March 2025, based on sightings collected from various sources, including MISP, Exploit-DB, Bluesky, Mastodon, GitHub Gists, The Shadowserver Foundation, Nuclei, and more. For further details, please visit this page.

The final section focuses on exploitations observed through The Shadowserver Foundation’s honeypot network.

March at a glance

Sightings repartition per day

Month at a glance

Repartition of all type of sightings per day for the month of March.

Top 5 Vulnerabilities evolution

Top 5 Vulnerabilities evolution

For more detailed information, check out the Vulnerability-Lookup dashboard:
https://vulnerability.circl.lu

Top 15 vulnerabilities of the month

Top 15 vulnerabilities of the month

VulnerabilityVendorProductCountSeverity
CVE-2025-29927vercelnext.js1679.1
CVE-2025-24813Apache Software FoundationApache Tomcat1289.2
CVE-2025-1974kubernetesingress-nginx869.8
CVE-2024-4577PHP GroupPHP839.8
CVE-2025-22224vmwareESXi809.3
CVE-2025-24201AppleiOS and iPadOS797.0
CVE-2025-2783GoogleChrome728.3
CVE-2025-30066tj-actionschanged-files678.6
CVE-2017-18368ZyXELp660hn-t1a_v1, p660hn-t1a_v2, 5200w-t609.8
CVE-2015-2051dlinkdir-645608.8
CVE-2018-10562dasannetworksgpon_router549.8
CVE-2025-22225vmwareESXi548.2
CVE-2025-23120VeeamBackup and Recovery529.9
CVE-2025-22226vmwareESXi487.1
CVE-2025-27363FreeTypeFreeType478.1

Evolution per week

Week 10

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-22224vmwareesxi729.3
CVE-2025-22225vmwareesxi508.2
CVE-2025-22226vmwareESXi447.1
CVE-2024-50302LinuxLinux397.8
CVE-2018-8639MicrosoftWindows 7227.8
CVE-2025-1316EdimaxIC-7100 IP Camera199.3
CVE-2023-20118CiscoCisco Small Business RV Series Router Firmware186.5
CVE-2024-43093GoogleAndroid187.8
CVE-2024-4577PHP GroupPHP189.8
CVE-2022-43769Hitachi VantaraPentaho Business Analytics Server168.8
CVE-2017-18368ZyXELp660hn-t1a_v1, p660hn-t1a_v2, 5200w-t149.8
CVE-2015-2051dlinkdir-645148.1
CVE-2021-44228Apache Software FoundationApache Log4j21310
CVE-2018-10562dasannetworksgpon_router139.8
CVE-2025-25012ElasticKibana13

CVE-2025-25012 has been reserved and is pending publication.

Insights from contributors

Week 11

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-24201AppleiOS and iPadOS707.1
CVE-2025-24813Apache Software FoundationApache Tomcat389.2
CVE-2024-4577PHP GroupPHP379.8
CVE-2025-27363FreeTypeFreeType328.1
CVE-2024-8176Red HatRed Hat Enterprise Linux 6267.2
CVE-2023-1234GoogleChrome254.3
CVE-2025-27636Apache Software FoundationApache Camel226.3
CVE-2025-24983MicrosoftWindows 10 Version 1507227.0
CVE-2025-25291SAML-Toolkitsruby-saml179.3
CVE-2025-25292SAML-Toolkitsruby-saml179.3
CVE-2025-21590Juniper NetworksJunos OS156.7
CVE-2017-18368ZyXELp660hn-t1a_v1, p660hn-t1a_v2, 5200w-t149.8
CVE-2015-2051dlinkdir-645148.8
CVE-2025-24993MicrosoftWindows 10 Version 1809127.8
CVE-2023-1389tp-linkTP-Link Archer AX21 (AX1800)128.8

Insights from contributors

Week 12

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-29927vercelnext.js689.1
CVE-2025-24813Apache Software FoundationApache Tomcat669.2
CVE-2025-30066tj-actionschanged-files518.6
CVE-2025-23120VeeamBackup and Recovery489.9
CVE-2024-27564dirk1983mm1.ltd source code275.8
CVE-2024-48248Backup & Replication Director228.6
CVE-2024-54471NAKIVO225.5
CVE-2024-9956GoogleChrome197.8
CVE-2025-24472FortinetFortiOS178.1
CVE-2024-4577PHP GroupPHP179.8
CVE-2025-2129Mage AI176.3
CVE-2025-0108Palo Alto NetworksCloud NGFW158.8
CVE-2025-1316EdimaxIC-7100 IP Camera149.3
CVE-2017-18368ZyXELp660hn-t1a_v1, p660hn-t1a_v2, 5200w-t149.8
CVE-2015-2051dlinkdir-645148.8

Week 13

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-29927vercelnext.js989.1
CVE-2025-1974kubernetesingress-nginx819.8
CVE-2025-2783GoogleChrome708.3
CVE-2025-1098kubernetesingress-nginx298.8
CVE-2025-2857MozillaFirefox2910
CVE-2025-24514kubernetesingress-nginx288.8
CVE-2025-1097kubernetesingress-nginx288.8
CVE-2025-22230vmwareVMware Tools267.8
CVE-2025-2825CrushFTPCrushFTP239.8
CVE-2025-24813Apache Software FoundationApache Tomcat199.2
CVE-2025-26633MicrosoftWindows 10 Version 1809197.0
CVE-2025-31160atop projectatop182.9
CVE-2025-24513kubernetesingress-nginx164.8
CVE-2019-9874sitecorecms169.8
CVE-2019-9875sitecorecms158.8

Insights from contributors

Continuous exploitation

The sightings used for this analysis were mainly collected through The Shadowserver Foundation’s honeypot network.

CVE-2024-4577 - PHP Group / PHP

PHP Group / PHP

Total of 180 sightings from 2024-06-12 (sighting type: seen from MISP) to 2025-03-30 (sighting type: exploited from The Shadowserver Foundation).

Mentioned in the bundle People’s Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations created on 2024-09-24.

MISP related events:

  • 3714e52f-0f9a-5bbd-a430-7051c621dd44 (2025-03-25)
  • a1e796df-2ad8-4c8d-8b69-737a004e72dd (2025-02-23)
  • 3c19819c-1dac-4ef2-bfed-be5efa7e0123 (2025-02-23)
  • 3c19819c-1dac-4ef2-bfed-be5efa7e0123 (first sighting, 2024-06-12)

CVE-2021-44228 - Apache Software Foundation / Apache Log4j2

Apache Software Foundation / Apache Log4j2

Total of 198 sightings from 2021-12-12 (sighting type: seen from Microsoft Blog) to 2025-03-30 (sighting type: exploited from The Shadowserver Foundation).

Mentioned in bundles:

Thank you

Thank you to all the contributors and our diverse sources!

If you want to contribute to the next report, you can create your account.

Feedback and Support

If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!
https://github.com/vulnerability-lookup/vulnerability-lookup/issues/