NVD disclosure day

Published threat advisories for April 3, 2025

CVE advisoryKnown Exploit

CVE-2025-31161

CrushFTP Authentication Bypass Allows Account Takeover.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass vulnerability exists in CrushFTP, potentially allowing unauthorized access to administrative accounts and full system compromise. This presents a significant business risk due to the ease of exploitation and potential for data breaches. Organizations should identify and update affected software

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-22457

Ivanti Connect Secure: Remote Code Execution Risk

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A remote, unauthenticated attacker can exploit a buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways to execute code. This poses a risk to organizations by potentially allowing unauthorized access and control of affected systems.

• CISA KEV