Jun 10, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-36412 SuiteCRM is an open-source Customer Relationship Management (CRM) software application.

  • CVSS 10

New critical Salesagility Suitecrm SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-35746 Buddypress Cover Project Buddypress Cover

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-37014 Langflow RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Langflow RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-31611 CVSS 9.1

SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.

CVE-2024-32167 CVSS 9.1

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have th...

CVE-2024-35746 CVSS 10

Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affec...

CVE-2024-36408 CVSS 9.6

SuiteCRM is an open-source Customer Relationship Management (CRM) software application.

CVE-2024-36409 CVSS 9.6

SuiteCRM is an open-source Customer Relationship Management (CRM) software application.

CVE-2024-36410 CVSS 9.6

SuiteCRM is an open-source Customer Relationship Management (CRM) software application.

CVE-2024-36411 CVSS 9.6

SuiteCRM is an open-source Customer Relationship Management (CRM) software application.

CVE-2024-36412 CVSS 10

SuiteCRM is an open-source Customer Relationship Management (CRM) software application.

CVE-2024-36415 CVSS 9.1

SuiteCRM is an open-source Customer Relationship Management (CRM) software application.

CVE-2024-37014 CVSS 9.8

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint an...

View critical disclosures

cvelogic Threat Intelligence