[Exploited by Ransomware: Unknown] Dassault Systèmes DELMIA Apriso has a code injection vulnerability, which may allow an attacker to execute arbitrary code.
[Exploited by Ransomware: Unknown] Dassault Systèmes DELMIA Apriso has a missing authorization vulnerability, which may allow an attacker to obtain privileged access to the corresponding program.
[CVE-2025-41244] Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability (CVSS v3.1: 7.8)
[Exploited by Ransomware: Unknown] Broadcom VMware Aria Operations and VMware Tools have a local privilege escalation vulnerability. A malicious local user with non-administrator privileges, who can access a virtual machine with VMware Tools installed, managed by Aria Operations, and with SDMP enabled, can exploit this vulnerability to escalate privileges to root on that virtual machine.
[Exploited by Ransomware: Known] XWiki Platform has an eval injection vulnerability, which may allow any visitor to execute arbitrary remote code by sending a request to SolrSearch.
Affected Platforms:
[CVE-2025-6204] Please refer to the official listed affected versions
[CVE-2025-24893] The official source has released a fix update for the vulnerability; please update to the relevant version https://jira.xwiki.org/browse/XWIKI-22149
Computer and Communications Center
Network Systems Group