May 17, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-32809 Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-33644

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-33552 8theme Xstore Core Privilege Escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical 8theme Xstore Core Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-22120 CVSS 9.1

Zabbix server can perform command execution for configured scripts.

CVE-2024-32511 CVSS 9.8

Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affe...

CVE-2024-32809 CVSS 10

Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc.

CVE-2024-33552 CVSS 9.8

Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a th...

CVE-2024-33567 CVSS 9.8

Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.Thi...

CVE-2024-33644 CVSS 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This...

CVE-2024-34919 CVSS 9.8

An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0...

CVE-2024-34982 CVSS 9.8

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary cod...

CVE-2024-35845 CVSS 9.1

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_i...

CVE-2024-4264 CVSS 9.8

A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when...

View critical disclosures

cvelogic Threat Intelligence