📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Information Technology and Cybersecurity HIGH 21m Global general Government and International Relations MEDIUM 24m Global general Enterprise Security / Information Technology HIGH 1h Global phishing Financial Services / Cryptocurrency CRITICAL 1h Global general Information Technology / Enterprise Software LOW 1h Global malware Government CRITICAL 1h Global supply_chain Technology HIGH 1h Global vulnerability Cybersecurity Software CRITICAL 3h Global malware Technology/Software Development HIGH 3h Global supply_chain Software Development and Technology CRITICAL 4h Global general Information Technology and Cybersecurity HIGH 21m Global general Government and International Relations MEDIUM 24m Global general Enterprise Security / Information Technology HIGH 1h Global phishing Financial Services / Cryptocurrency CRITICAL 1h Global general Information Technology / Enterprise Software LOW 1h Global malware Government CRITICAL 1h Global supply_chain Technology HIGH 1h Global vulnerability Cybersecurity Software CRITICAL 3h Global malware Technology/Software Development HIGH 3h Global supply_chain Software Development and Technology CRITICAL 4h Global general Information Technology and Cybersecurity HIGH 21m Global general Government and International Relations MEDIUM 24m Global general Enterprise Security / Information Technology HIGH 1h Global phishing Financial Services / Cryptocurrency CRITICAL 1h Global general Information Technology / Enterprise Software LOW 1h Global malware Government CRITICAL 1h Global supply_chain Technology HIGH 1h Global vulnerability Cybersecurity Software CRITICAL 3h Global malware Technology/Software Development HIGH 3h Global supply_chain Software Development and Technology CRITICAL 4h

🛡️ CVE Intelligence Center

Common Vulnerabilities & Exposures — Security Intelligence Database

CVE ID Severity CVSS Description Status Published
CVE-2025-4632 Critical 9.0
Samsung MagicINFO 9 Server Path Traversal Vulnerability — Samsung MagicINFO 9 Server contains a path traversal vulnerabi…
⚡ Exploit ✅ Patch May 22, 2025
CVE-2025-4428 Critical 9.0
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability — Ivanti Endpoint Manager Mobile (EPMM) contains a co…
⚡ Exploit ✅ Patch May 19, 2025
CVE-2025-4427 Critical 9.0
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability — Ivanti Endpoint Manager Mobile (EPMM) contai…
⚡ Exploit ✅ Patch May 19, 2025
CVE-2024-11182 Critical 9.0
MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability — MDaemon Email Server contains a cross-site scripting (XS…
⚡ Exploit ✅ Patch May 19, 2025
CVE-2024-27443 Critical 9.0
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability — Zimbra Collaboration contains a cros…
⚡ Exploit ✅ Patch May 19, 2025
CVE-2023-38950 Critical 9.0
ZKTeco BioTime Path Traversal Vulnerability — ZKTeco BioTime contains a path traversal vulnerability in the iclock API t…
⚡ Exploit ✅ Patch May 19, 2025
CVE-2025-27920 Critical 9.0
Srimax Output Messenger Directory Traversal Vulnerability — Srimax Output Messenger contains a directory traversal vulne…
⚡ Exploit ✅ Patch May 19, 2025
CVE-2024-12987 Critical 9.0
DrayTek Vigor Routers OS Command Injection Vulnerability — DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain a…
⚡ Exploit ✅ Patch May 15, 2025
CVE-2025-42999 Critical 9.0
SAP NetWeaver Deserialization Vulnerability — SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization…
⚡ Exploit ✅ Patch May 15, 2025
CVE-2025-32756 Critical 9.0
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability — Fortinet FortiFone, FortiVoice, FortiNDR and Fort…
⚡ Exploit ✅ Patch May 14, 2025
CVE-2025-30400 Critical 9.0
Microsoft Windows DWM Core Library Use-After-Free Vulnerability — Microsoft Windows DWM Core Library contains a use-afte…
⚡ Exploit ✅ Patch May 13, 2025
CVE-2025-30397 Critical 9.0
Microsoft Windows Scripting Engine Type Confusion Vulnerability — Microsoft Windows Scripting Engine contains a type con…
⚡ Exploit ✅ Patch May 13, 2025
CVE-2025-32701 Critical 9.0
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability — Microsoft Windows Common Log File …
⚡ Exploit ✅ Patch May 13, 2025
CVE-2025-32709 Critical 9.0
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability — Microsoft Windows Ancillary Funct…
⚡ Exploit ✅ Patch May 13, 2025
CVE-2025-32706 Critical 9.0
Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability — Microsoft Windows Comm…
⚡ Exploit ✅ Patch May 13, 2025
CVE-2025-47729 Critical 9.0
TeleMessage TM SGNL Hidden Functionality Vulnerability — TeleMessage TM SGNL contains a hidden functionality vulnerabili…
⚡ Exploit ✅ Patch May 12, 2025
CVE-2024-6047 Critical 9.0
GeoVision Devices OS Command Injection Vulnerability — Multiple GeoVision devices contain an OS command injection vulner…
⚡ Exploit ✅ Patch May 7, 2025
CVE-2024-11120 Critical 9.0
GeoVision Devices OS Command Injection Vulnerability — Multiple GeoVision devices contain an OS command injection vulner…
⚡ Exploit ✅ Patch May 7, 2025
CVE-2025-27363 Critical 9.0
FreeType Out-of-Bounds Write Vulnerability — FreeType contains an out-of-bounds write vulnerability when attempting to p…
⚡ Exploit ✅ Patch May 6, 2025
CVE-2025-3248 Critical 9.0
Langflow Missing Authentication Vulnerability — Langflow contains a missing authentication vulnerability in the /api/v1/…
⚡ Exploit ✅ Patch May 5, 2025
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.