Jul 22, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-39250 Efrotech Timetrax SQL Injection

  • CVSS 9.8

New critical Efrotech Timetrax SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-40502 Angeljudesuarez Hospital Management System SQL Injection

  • CVSS 9.8

New critical Angeljudesuarez Hospital Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-6793 Ni Veristand RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Ni Veristand RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-28698 CVSS 9.8

Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted sc...

CVE-2024-38944 CVSS 9.8

An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generat...

CVE-2024-39250 CVSS 9.8

EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web int...

CVE-2024-39686 CVSS 9.8

Bert-VITS2 is the VITS2 Backbone with multilingual bert.

CVE-2024-40502 CVSS 9.8

SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via...

CVE-2024-6793 CVSS 9.8

A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution.

CVE-2024-6794 CVSS 9.8

A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution.

CVE-2024-6806 CVSS 9.8

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources.

CVE-2024-6912 CVSS 9.3

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.T...

CVE-2024-6913 CVSS 9.3

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This is...

View critical disclosures

cvelogic Threat Intelligence