Jul 1, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-38366 trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-38513 Gofiber Fiber

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-39251 An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2....

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-28200 CVSS 9.1

The N-central server is vulnerable to an authentication bypass of the user interface.

CVE-2024-37762 CVSS 9.9

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

CVE-2024-38366 CVSS 10

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.

CVE-2024-38368 CVSS 9.3

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.

CVE-2024-38476 CVSS 9.8

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution v...

CVE-2024-38513 CVSS 10

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issu...

CVE-2024-39236 CVSS 9.8

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py.

CVE-2024-39251 CVSS 10

An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensit...

CVE-2024-39309 CVSS 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.

CVE-2024-5322 CVSS 9.1

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentica...

View critical disclosures

cvelogic Threat Intelligence