May 22, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-33226 An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 al...

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-51637 Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability.

  • CVSS 9.8
  • Remote code execution exposure

New critical Santesoft Sante Pacs Server RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-35409 WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

  • CVSS 9.8

New critical Webidsupport Webid SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-51637 CVSS 9.8

Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability.

CVE-2024-25738 CVSS 9.1

A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 befo...

CVE-2024-29849 CVSS 9.8

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

CVE-2024-33226 CVSS 9.9

An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges an...

CVE-2024-3495 CVSS 9.8

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up...

CVE-2024-35409 CVSS 9.8

WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

CVE-2024-4267 CVSS 9.8

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5.

CVE-2024-4443 CVSS 9.8

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via...

CVE-2024-5147 CVSS 9.8

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...

View critical disclosures

cvelogic Threat Intelligence