Jan 9, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-55225 Dani-garcia Vaultwarden privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Dani-garcia Vaultwarden privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-13279 Two-factor Authentication Project Two-factor Authentication

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-13280 Persistent Login Project Persistent Login

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-28354 CVSS 9.8

An issue was discovered in Opsview Monitor Agent 6.8.

CVE-2024-13278 CVSS 9.1

Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.

CVE-2024-13279 CVSS 9.8

Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentica...

CVE-2024-13280 CVSS 9.8

Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: fr...

CVE-2024-13281 CVSS 9.1

Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 befor...

CVE-2024-13285 CVSS 9.8

Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.

CVE-2024-46505 CVSS 9.1

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

CVE-2024-54724 CVSS 9.8

PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.

CVE-2024-55224 CVSS 9.6

An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payloa...

CVE-2024-55225 CVSS 9.8

An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administra...

View critical disclosures

cvelogic Threat Intelligence