Sep 5, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-7591 Kemptechnologies Loadmaster Command Injection

  • CVSS 10

New critical Kemptechnologies Loadmaster Command Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-44727 Angeljudesuarez Event Management System SQL Injection

  • CVSS 9.8

New critical Angeljudesuarez Event Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-45158 An issue was discovered in Mbed TLS 3.6 before 3.6.1.

  • CVSS 9.8

New critical Trustedfirmware Mbed Tls Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-24759 CVSS 9.3

MindsDB is a platform for building artificial intelligence from enterprise data.

CVE-2024-42885 CVSS 9.1

SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data....

CVE-2024-44727 CVSS 9.8

Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.

CVE-2024-45158 CVSS 9.8

An issue was discovered in Mbed TLS 3.6 before 3.6.1.

CVE-2024-45159 CVSS 9.8

An issue was discovered in Mbed TLS 3.x before 3.6.1.

CVE-2024-7591 CVSS 10

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and...

CVE-2024-8395 CVSS 9.3

FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no auth...

CVE-2024-8468 CVSS 9.8

SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php,...

CVE-2024-8469 CVSS 9.8

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee...

CVE-2024-8470 CVSS 9.8

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/va...

View critical disclosures

cvelogic Threat Intelligence