Nov 7, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Android Framework added to CISA KEV — confirmed in-the-wild exploitation.
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2019-16278 Nostromo nhttpd Directory Traversal

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Nostromo Nhttpd RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-50766 Oretnom23 Survey Application System SQL Injection

  • CVSS 9.8

New critical Oretnom23 Survey Application System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2019-20461 An issue was discovered on Alecto IVM-100 2019-11-12 devices.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Palo Alto Networks Expedition Missing Authentication

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2019-20457 CVSS 9.1

An issue was discovered on Brother MFC-J491DW C1806180757 devices.

CVE-2019-20461 CVSS 9.8

An issue was discovered on Alecto IVM-100 2019-11-12 devices.

CVE-2024-47073 CVSS 9.3

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends.

CVE-2024-50766 CVSS 9.8

SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.

CVE-2024-51504 CVSS 9.1

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only im...

View critical disclosures

cvelogic Threat Intelligence