Jul 19, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-39962 Dlink Dir-823x Firmware RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Dlink Dir-823x Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-6205 Payplus Payment Gateway SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Payplus Payment Gateway SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-35198 TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-29736 CVSS 9.1

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SS...

CVE-2024-35198 CVSS 9.8

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production.

CVE-2024-39962 CVSS 9.8

D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerabilit...

CVE-2024-41603 CVSS 9.6

Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.

CVE-2024-6205 CVSS 9.8

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL stat...

View critical disclosures

cvelogic Threat Intelligence