Jul 11, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-6397 Instawp Connect Auth Bypass

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Instawp Connect Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-6624 Parorrey Json Api User Privilege Escalation

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Parorrey Json Api User Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-6407 Schneider-electric Whc-5918a Firmware

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-36435 CVSS 9.8

An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules).

CVE-2024-40618 CVSS 9.6

Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-...

CVE-2024-6385 CVSS 9.6

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, a...

CVE-2024-6397 CVSS 9.8

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, a...

CVE-2024-6407 CVSS 9.8

CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to...

CVE-2024-6624 CVSS 9.8

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3.

View critical disclosures

cvelogic Threat Intelligence