Jan 7, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Mitel MiCollab: 2 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-41713 Mitel MiCollab Path Traversal

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Mitel MiCollab Path Traversal is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-22133 WeGIA is a web manager for charitable institutions.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2022-41572 An issue was discovered in EyesOfNetwork (EON) through 5.3.11.

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Eyesofnetwork Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-41572 CVSS 9.8

An issue was discovered in EyesOfNetwork (EON) through 5.3.11.

CVE-2024-35532 CVSS 9.1

An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arb...

CVE-2024-50658 CVSS 9.8

Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsB...

CVE-2024-50660 CVSS 9.8

File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality

CVE-2024-54819 CVSS 9.1

I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/...

CVE-2024-55414 CVSS 9.8

A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping p...

CVE-2025-0247 CVSS 9.8

Memory safety bugs present in Firefox 133 and Thunderbird 133.

CVE-2025-21624 CVSS 9.8

ClipBucket V5 provides open source video hosting with PHP.

CVE-2025-22133 CVSS 9.9

WeGIA is a web manager for charitable institutions.

View critical disclosures

cvelogic Threat Intelligence