Jul 5, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-27710 Eskooly privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Eskooly privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-27712 Eskooly privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Eskooly privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-29319 Personal-management-system Personal Management System SSRF

  • CVSS 9.8

New critical Personal-management-system Personal Management System SSRF (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-23997 CVSS 9.6

Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.

CVE-2024-23998 CVSS 9.6

goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.

CVE-2024-27709 CVSS 9.8

SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of...

CVE-2024-27710 CVSS 9.8

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authe...

CVE-2024-27712 CVSS 9.8

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User...

CVE-2024-29319 CVSS 9.8

Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file.

CVE-2024-37768 CVSS 9.1

14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.

CVE-2024-38346 CVSS 9.8

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hype...

CVE-2024-39028 CVSS 9.8

An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

CVE-2024-39864 CVSS 9.8

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled vi...

View critical disclosures

cvelogic Threat Intelligence