Jul 18, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-39911 1Panel is a web-based linux server management control panel.

  • CVSS 10

New critical Fit2cloud 1panel SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-40628 Fit2cloud Jumpserver Info Disclosure

  • CVSS 10

New critical Fit2cloud Jumpserver Info Disclosure (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-40629 Fit2cloud Jumpserver RCE

  • CVSS 10
  • Remote code execution exposure

New critical Fit2cloud Jumpserver RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-0857 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc.

CVE-2024-39173 CVSS 9.8

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calcul...

CVE-2024-39907 CVSS 9.8

1Panel is a web-based linux server management control panel.

CVE-2024-39911 CVSS 10

1Panel is a web-based linux server management control panel.

CVE-2024-40628 CVSS 10

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access t...

CVE-2024-40629 CVSS 10

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access t...

CVE-2024-41184 CVSS 9.8

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur.

CVE-2024-5618 CVSS 9.9

Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing...

CVE-2024-5619 CVSS 9.6

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Inc...

CVE-2024-6164 CVSS 9.8

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter.

View critical disclosures

cvelogic Threat Intelligence