Sep 13, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Ivanti Cloud Services Appliance added to CISA KEV — confirmed in-the-wild exploitation.
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-8190 Ivanti Cloud Services Appliance OS Command Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Ivanti Cloud Services Appliance RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-41874 Adobe Coldfusion RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Adobe Coldfusion RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-44430 Mayurik Best Free Law Office Management SQL Injection

  • CVSS 9.8

New critical Mayurik Best Free Law Office Management SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Ivanti Cloud Services Appliance OS Command Injection

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-41874 CVSS 9.8

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in ar...

CVE-2024-44430 CVSS 9.8

SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sens...

CVE-2024-46044 CVSS 9.8

CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

CVE-2024-46045 CVSS 9.8

Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.

CVE-2024-46046 CVSS 9.8

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.

CVE-2024-46048 CVSS 9.8

Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

CVE-2024-46049 CVSS 9.8

Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.

View critical disclosures

cvelogic Threat Intelligence