Want to stay ahead of threats in 2025? This research report is all you need to stay updated.

Vulnerabilities

CVE ID CVSS Score Short Summary Link
CVE-2025-1974 9.8 Critical Remote Code Execution in Kubernetes Ingress-NGINX via Unsanitized Annotations: CVE-2025-1974 Decoded Click here
CVE-2025-47812 10 Wing FTP Server Hit by Critical RCE Vulnerability: CVE-2025-47812 Explained Click here
CVE-2025-53771 7.1 Critical Authentication Bypass in SharePoint via Spoofed Referer Header: A Deep Dive into CVE-2025-53771 Click here
CVE‑2025‑6218 7.8 High-Severity Directory Traversal in WinRAR Allows Remote Code Execution: CVE-2025-6218 Explained Click here
CVE-2025-53770 9.8 Widespread SharePoint Takeover via Auth Bypass and ASPX Web Shells: CVE-2025-53770 Analyzed Click here
CVE-2025-22225 8.2 Critical VM Escape in VMware ESXi via Arbitrary Kernel Write: CVE-2025-22225 Decoded Click here
CVE-2025-25257 9.6 Critical Unauthenticated SQL Injection to Root RCE in FortiWeb's Fabric Connector: CVE-2025-25257 Decoded Click here
CVE-2025-27831 9.8 Critical Buffer Overflow in Ghostscript DOCXWRITE/TXTWRITE via Malformed Text: CVE-2025-27831 Decoded Click here
CVE-2025-22226 7.1 High-Severity Information Disclosure in VMware ESXi, Workstation, and Fusion HGFS via Out-of-Bounds Read: CVE-2025-22226 Explained Click here
CVE-2025-22224 9.3 Critical VM Escape via TOCTOU in VMware ESXi and Workstation: CVE-2025-22224 Explained Click here
CVE-2025-2783 8.8 Zero-Click Chrome Sandbox Escape via Mojo Flaw: CVE-2025-2783 Breakdown Click here
CVE-2025-29927 9.1 Critical Authorization Bypass in Next.js Middleware via Spoofed Headers: CVE-2025-29927 Decoded Click here
CVE-2025-24813 9.8 Path equivalence flaw enabling RCE and file injection Click here
CVE-2025-21298 9.8 Zero-click RCE via malicious RTF in Outlook Click here

Get Started

See Fidelis Security platforms in action. Learn how our fast scalable platforms provide full visibility, deep insights, and rapid response to help security teams worldwide protect, detect, respond, and neutralize against advanced cyber adversaries.