Dec 4, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • CyberPersons CyberPanel added to CISA KEV — confirmed in-the-wild exploitation.
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-51378 CyberPanel Incorrect Default Permissions

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.

Critical exposure

CVE-2018-9416 In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause.

  • CVSS 10

New critical Google Android Memory Corruption (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-40744 Convert Forms Project Convert Forms

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-9416 CVSS 10

In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause.

CVE-2024-10576 CVSS 9.4

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver.

CVE-2024-40744 CVSS 9.8

Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.

CVE-2024-48453 CVSS 9.8

An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function

CVE-2024-54221 CVSS 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-se...

CVE-2024-54661 CVSS 9.8

readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.

View critical disclosures

cvelogic Threat Intelligence