The first quarter of 2025 saw 159 CVE identifiers exploited in the wild, up from 151 in Q4 2024. According to VulnCheck’s latest report, 28.3% of these vulnerabilities were exploited within just one day of their CVE disclosure—representing 45 security flaws weaponized almost immediately after becoming public.
The exploitation timeline shows concerning patterns: 45 flaws exploited within 24 hours, 14 within a month, and another 45 within a year of disclosure.
## Most Targeted Systems
Content Management Systems (CMSes) topped the list of exploited technologies, followed by:
1. Content Management Systems (35)
2. Network Edge Devices (29)
3. Operating Systems (24)
4. Open Source Software (14)
5. Server Software (14)
The most frequently exploited products came from major vendors:
– Microsoft Windows (15)
– Broadcom VMware (6)
– Cyber PowerPanel (5)
– Litespeed Technologies (4)
– TOTOLINK Routers (4)
## Vulnerability Tracking Challenges
VulnCheck reported an average of 11.4 Known Exploited Vulnerabilities (KEVs) disclosed weekly and 53 monthly. While CISA added 80 vulnerabilities to its KEV catalog during Q1, only 12 had no prior public evidence of exploitation.
Of the 159 vulnerabilities, 25.8% are still awaiting or undergoing analysis by the NIST National Vulnerability Database, and 3.1% have been assigned “Deferred” status.
## Broader Threat Landscape
Verizon’s 2025 Data Breach Investigations Report indicates vulnerability exploitation as an initial access vector grew by 34%, now accounting for 20% of all intrusions.
Mandiant’s data confirms exploits remain the most observed initial infection vector for the fifth consecutive year at 33% of intrusions—slightly down from 38% in 2023 but consistent with 2022’s 32%. Stolen credentials have now overtaken phishing as the second most common initial access method.
Despite these challenges, the global median dwell time—the period between compromise and detection—stands at 11 days, just one day longer than in 2023, suggesting defenders continue improving their detection capabilities.
