Dec 2, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-10905 Sailpoint Identityiq

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2018-9418 Google Android Code Execution

  • CVSS 9.8
  • Remote code execution exposure

New critical Google Android Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2018-9430 Google Android RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Google Android RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-9418 CVSS 9.8

In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check.

CVE-2018-9430 CVSS 9.8

In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check.

CVE-2024-10905 CVSS 10

IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8....

CVE-2024-46909 CVSS 9.8

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in...

CVE-2024-52724 CVSS 9.8

ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.

CVE-2024-52732 CVSS 9.1

Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused.

CVE-2024-53477 CVSS 9.8

JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

CVE-2024-53900 CVSS 9.1

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

CVE-2024-53990 CVSS 9.2

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.

CVE-2024-8785 CVSS 9.8

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an exis...

View critical disclosures

cvelogic Threat Intelligence