Oct 10, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-45115 Adobe Commerce Privilege Escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Adobe Commerce Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-47636 Eyecix Jobsearch Wp Job Board Deserialization

  • CVSS 9.8

New critical Eyecix Jobsearch Wp Job Board Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-9796 Internet-formation Wp-advanced-search SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Internet-formation Wp-advanced-search SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-45115 CVSS 9.8

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that...

CVE-2024-47636 CVSS 9.8

Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: fr...

CVE-2024-9201 CVSS 9.4

The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter o...

CVE-2024-9487 CVSS 9.5

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authen...

CVE-2024-9796 CVSS 9.8

The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, a...

CVE-2024-9798 CVSS 9

The health endpoint is public so everybody can see a list of all services.

CVE-2024-9822 CVSS 9.8

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5.

View critical disclosures

cvelogic Threat Intelligence