Apr 26, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-32766 Qnap Qts Command Injection

  • CVSS 10

New critical Qnap Qts Command Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-32764 Myqnapcloud Link privilege escalation

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Myqnapcloud Link privilege escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-28322 Puneethreddyhc Event Management SQL Injection

  • CVSS 9.8

New critical Puneethreddyhc Event Management SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-47222 CVSS 9.6

An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on.

CVE-2024-25343 CVSS 9.1

Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.

CVE-2024-28322 CVSS 9.8

SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to r...

CVE-2024-30804 CVSS 9.8

An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via cr...

CVE-2024-31601 CVSS 9.8

An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.

CVE-2024-32764 CVSS 9.9

A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link.

CVE-2024-32766 CVSS 10

An OS command injection vulnerability has been reported to affect several QNAP operating system versions.

CVE-2024-32880 CVSS 9.1

pyload is an open-source Download Manager written in pure Python.

CVE-2024-32881 CVSS 9.8

Danswer is the AI Assistant connected to company's docs, apps, and people.

CVE-2024-33344 CVSS 9.8

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers t...

View critical disclosures

cvelogic Threat Intelligence