Latest Cyber Threat Data

CISA Known Exploited Vulnerabilities (Top 10)

CVE-2025-32432

Vendor: Craft CMS

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Details

CVE-2025-54068

Vendor: Laravel

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Details

CVE-2025-43510

Vendor: Apple

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.

Details

CVE-2025-43520

Vendor: Apple

Apple watchOS, iOS, iPadOS, macOS, visionOS, tvOS, and iPadOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.

Details

CVE-2025-31277

Vendor: Apple

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.

Details

CVE-2026-20131

Vendor: Cisco

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

Details

CVE-2025-66376

Vendor: Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.

Details

CVE-2026-20963

Vendor: Microsoft

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

Details

CVE-2025-47813

Vendor: Wing FTP Server

Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.

Details

CVE-2026-3910

Vendor: Google

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Details

MITRE ATT&CK Techniques (Top 10)

Last updated: March 21, 2026, 8:08 p.m.