Jan 6, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-20148 In wlan STA FW, there is a possible out of bounds write due to improper input validation.

  • CVSS 9.8
  • Remote code execution exposure

New critical Google Android Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-55529 Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.

  • CVSS 9.8
  • Remote code execution exposure

New critical Zblogcn Z-blogphp RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-56828 File Upload vulnerability in ChestnutCMS through 1.5.0.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-20148 CVSS 9.8

In wlan STA FW, there is a possible out of bounds write due to improper input validation.

CVE-2024-46622 CVSS 9.8

An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11...

CVE-2024-53931 CVSS 9.1

The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no p...

CVE-2024-53932 CVSS 9.1

The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android ena...

CVE-2024-54879 CVSS 9.1

SeaCMS V13.1 is vulnerable to Incorrect Access Control.

CVE-2024-54880 CVSS 9.1

SeaCMS V13.1 is vulnerable to Incorrect Access Control.

CVE-2024-55529 CVSS 9.8

Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.

CVE-2024-5594 CVSS 9.1

OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected...

CVE-2024-56828 CVSS 9.8

File Upload vulnerability in ChestnutCMS through 1.5.0.

CVE-2025-21613 CVSS 9.2

go-git is a highly extensible git implementation library written in pure Go.

View critical disclosures

cvelogic Threat Intelligence