Dec 9, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-37143 Dell Data Lakehouse

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-54932 Lopalopa E-learning Management System SQL Injection

  • CVSS 9.8

New critical Lopalopa E-learning Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-54934 Lopalopa E-learning Management System SQL Injection

  • CVSS 9.8

New critical Lopalopa E-learning Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-37143 CVSS 10

Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8....

CVE-2024-46455 CVSS 9.8

unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

CVE-2024-47578 CVSS 9.1

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application.

CVE-2024-53441 CVSS 9.1

An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.

CVE-2024-53552 CVSS 9.8

CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

CVE-2024-54932 CVSS 9.8

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

CVE-2024-54934 CVSS 9.8

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.

CVE-2024-55636 CVSS 9.8

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before...

CVE-2024-55637 CVSS 9.8

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before...

CVE-2024-55638 CVSS 9.8

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7....

View critical disclosures

cvelogic Threat Intelligence