Top Notable Enterprise Remote Vulnerabilities

07-11-2025
A concise overview for IS leaders, emphasizing actively exploited vulnerabilities, their significance, and the critical need for remediation.
Currently Trending Enterprise Remote Vulnerabilities
Trending CVEs
Vulnerability
Notables
CVE-2025-11953
Vulnerability
React Native Community CLI RCE
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-64439
Vulnerability
LangGraph JsonPlusSerializer RCE
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-34299
Vulnerability
Monsta FTP RCE
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-11833
Vulnerability
The Post SMTP WordPress Plugin Unauthorized Data Access
Notables
Potential Risk of Exploitation
CVE-2025-9491
Vulnerability
Microsoft Windows LNK File UI RCE
Notables
Potential Risk of Exploitation
CVE-2025-11749
Vulnerability
AI Engine WordPress Plugin Sensitive Information Exposure
Notables
Limited Public Information Available
CVE-2025-64095
Vulnerability
DNN (formerly DotNetNuke) Arbitrary File Overwrite
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-20354
Vulnerability
Cisco Unified CCX RMI Arbitrary File Upload
Notables
Potential Risk of Exploitation
CVE-2025-20358
Vulnerability
Cisco Unified CCX Authentication Bypass
Notables
Potential Risk of Exploitation
CVE-2025-47776
Vulnerability
Mantis Bug Tracker Authentication Bypass
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-37736
Vulnerability
Elastic Cloud Enterprise Privilege Escalation
Notables
Potential Risk of Exploitation
CVE-2025-8489
Vulnerability
King Addons for Elementor WordPress Plugin Privilege Escalation
Notables
Potential Risk of Exploitation
CVE-2025-64132
Vulnerability
Jenkins MCP Server Plugin Missing Authorization
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-11202
Vulnerability
win-cli-mcp-server Command Injection
Notables
Potential Risk of Exploitation
CVE-2025-5397
Vulnerability
Noo JobMonster WordPress Theme Authentication Bypass
Notables
Limited Public Information Available
CVE-2025-49825
Vulnerability
Teleport Community Edition RCE
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-64459
Vulnerability
Django SQL Injection via _connector Keyword
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-64458
Vulnerability
Django DoS via Unicode Redirects
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-55343
Vulnerability
Quipux Authenticated SQL injection
Notables
Limited Public Information Available
CVE-2025-55341
Vulnerability
Quipux Cross-Site Scripting
Notables
Limited Public Information Available