Dec 12, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-55877 XWiki Platform is a generic wiki platform.

  • CVSS 9.9
  • Remote code execution exposure

New critical Xwiki RCE (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-55662 XWiki Platform is a generic wiki platform.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-54810 Phpgurukul Pre-school Enrollment System SQL Injection

  • CVSS 9.8

New critical Phpgurukul Pre-school Enrollment System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-21575 CVSS 9.2

ComfyUI-Impact-Pack is vulnerable to Path Traversal.

CVE-2024-49147 CVSS 9.3

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webs...

CVE-2024-54810 CVSS 9.8

A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0...

CVE-2024-54811 CVSS 9.8

A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary S...

CVE-2024-54842 CVSS 9.8

A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno pa...

CVE-2024-55099 CVSS 9.8

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers...

CVE-2024-55875 CVSS 9.8

http4k is a functional toolkit for Kotlin HTTP applications.

View critical disclosures

cvelogic Threat Intelligence