Top Notable Enterprise Remote Vulnerabilities

12-12-2025
A concise overview for IS leaders, emphasizing actively exploited vulnerabilities, their significance, and the critical need for remediation.
Currently Trending Enterprise Remote Vulnerabilities
Trending CVEs
Vulnerability
Notables
CVE-2025-55182
Vulnerability
React Server Components RCE (React2Shell)
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-40549
Vulnerability
SolarWinds Serv U Path Traversal
Notables
Potential Risk of Exploitation
CVE-2025-40548
Vulnerability
SolarWinds Serv U Code Execution
Notables
Potential Risk of Exploitation
CVE-2025-64756
Vulnerability
Node-glob Command Injection
Notables
Limited Public Information Available
CVE-2025-58034
Vulnerability
Fortinet FortiWeb Command Injection
Notables
Potential Risk of Exploitation
CVE-2025-64446
Vulnerability
Fortinet FortiWeb Path Traversal
Notables
Potential Risk of Exploitation
CVE-2025-11001
Vulnerability
7-Zip ZIP File Parsing Directory Traversal
Notables
Potential Risk of Exploitation
CVE-2025-8943
Vulnerability
Flowise RCE
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-10437
Vulnerability
Webpack Management System SQL Injection
Notables
Limited Public Information Available
CVE-2025-11230
Vulnerability
HAProxy inefficient Algorithmic Complexity Leads to DoS
Notables
Potential Risk of Exploitation
CVE-2025-9501
Vulnerability
W3 Total Cache WordPress Plugin Command Injection
Notables
Limited Public Information Available
CVE-2025-34291
Vulnerability
Langflow AI Account takeover
Notables
Proof of Concept Available, Actively Exploited
CVE-2025-42880
Vulnerability
SAP Solution Manager Authenticated RCE
Notables
Potential Risk of Exploitation
CVE-2025-42928
Vulnerability
SAP jConnect Authenticated RCE
Notables
Potential Risk of Exploitation
CVE-2025-6389
Vulnerability
WordPress Sneeit Framework plugin RCE
Notables
Potential Risk of Exploitation
CVE-2025-66516
Vulnerability
Apache Tika XXE
Notables
Potential Risk of Exploitation
CVE-2025-64671
Vulnerability
GitHub Copilot for JetBrains RCE
Notables
Potential Risk of Exploitation
CVE-2025-66550
Vulnerability
Nextcloud Calendar Arbitrary Download
Notables
Potential Risk of Exploitation
CVE-2025-65036
Vulnerability
XWiki RCE via Velocity Macro
Notables
Potential Risk of Exploitation
CVE-2025-61757
Vulnerability
Oracle Identity Manager Pre-Auth RCE
Notables
Proof of Concept Available, Actively Exploited