Feb 14, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-25215 Sherlock Employee Management System SQL Injection

  • CVSS 9.8

New critical Sherlock Employee Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-25216 Sherlock Employee Management System SQL Injection

  • CVSS 9.8

New critical Sherlock Employee Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-25217 Oretnom23 Online Medicine Ordering System SQL Injection

  • CVSS 9.8

New critical Oretnom23 Online Medicine Ordering System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-24300 CVSS 9.8

4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control.

CVE-2024-25215 CVSS 9.8

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

CVE-2024-25216 CVSS 9.8

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.

CVE-2024-25217 CVSS 9.8

Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/vi...

CVE-2024-25220 CVSS 9.8

Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.

CVE-2024-25222 CVSS 9.8

Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.

CVE-2024-25223 CVSS 9.8

Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder...

CVE-2024-26260 CVSS 9.8

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote atta...

CVE-2024-26261 CVSS 9.8

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability.

CVE-2024-26264 CVSS 9.8

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible wi...

View critical disclosures

cvelogic Threat Intelligence