Aug 1, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-38770

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-41961 Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services.

  • CVSS 9.6

New critical disclosure (CVSS 9.6) — high severity with a short public awareness window before exploit material typically surfaces.

High-risk exposure

CVE-2024-7093 Dispatch's notification service uses Jinja templates to generate messages to users.

  • CVSS 9.4
  • Remote code execution exposure

New critical-severity CVE in today's window — elevated exposure signal, early in the lifecycle.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exch...

CVE-2024-38770 CVSS 9.8

Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication...

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin...

CVE-2024-41259 CVSS 9.1

Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account informat...

CVE-2024-41961 CVSS 9.6

Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services.

CVE-2024-7093 CVSS 9.4

Dispatch's notification service uses Jinja templates to generate messages to users.

CVE-2024-7332 CVSS 9.3

A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224.

View critical disclosures

cvelogic Threat Intelligence