Apr 22, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-32039 FreeRDP is a free implementation of the Remote Desktop Protocol.

  • CVSS 9.8

New critical Fedoraproject Fedora Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-32041 FreeRDP is a free implementation of the Remote Desktop Protocol.

  • CVSS 9.8

New critical Fedoraproject Fedora Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-32458 FreeRDP is a free implementation of the Remote Desktop Protocol.

  • CVSS 9.8

New critical Fedoraproject Fedora Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-27349 CVSS 9.1

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before...

CVE-2024-27574 CVSS 9.1

SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the inf...

CVE-2024-31545 CVSS 9.4

Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.

CVE-2024-31666 CVSS 9.8

An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.

CVE-2024-32039 CVSS 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol.

CVE-2024-32041 CVSS 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol.

CVE-2024-32238 CVSS 9.8

H3C ER8300G2-X is vulnerable to Incorrect Access Control.

CVE-2024-32458 CVSS 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol.

CVE-2024-32459 CVSS 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol.

View critical disclosures

cvelogic Threat Intelligence