Oct 8, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Windows: 2 CVEs added to CISA KEV today.
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-43047 Qualcomm Multiple Chipsets Use-After-Free

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Qualcomm Multiple Chipsets Memory Corruption is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-43468 Microsoft Configuration Manager SQL Injection

  • CVSS 9.8
  • Remote code execution exposure

New critical Microsoft Configuration Manager RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-8911 Latepoint SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Latepoint SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Windows Management Console Remote Code Execution

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-3057 CVSS 9.8

A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

Windows Netlogon Elevation of Privilege Vulnerability

CVE-2024-43468 CVSS 9.8

Microsoft Configuration Manager SQL Injection

CVE-2024-44349 CVSS 9.8

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL comma...

CVE-2024-45918 CVSS 9.8

Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

CVE-2024-47553 CVSS 9.4

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0).

CVE-2024-47562 CVSS 9.3

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0).

CVE-2024-8884 CVSS 9.8

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when at...

CVE-2024-8911 CVSS 9.8

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5....

CVE-2024-8943 CVSS 9.8

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12.

View critical disclosures

cvelogic Threat Intelligence