Jun 28, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-3816 Conceptintermedia S\@m Cms SQL Injection

  • CVSS 9.8

New critical Conceptintermedia S\@m Cms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-39349 Synology Bc500 Firmware Buffer Overflow

  • CVSS 9.8

New critical Synology Bc500 Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-39704 Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools.

CVE-2024-37371 CVSS 9.1

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending messa...

CVE-2024-3816 CVSS 9.8

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar.

CVE-2024-39349 CVSS 9.8

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and...

CVE-2024-39704 CVSS 9.8

Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev.

CVE-2024-5827 CVSS 9.8

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs.

View critical disclosures

cvelogic Threat Intelligence