Jan 13, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • BeyondTrust Privileged Remote Access (PRA) And Remote Support (RS) added to CISA KEV — confirmed in-the-wild exploitation.
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-48365 Qlik Sense HTTP Tunneling

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Qlik Sense RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-46479 Venki Supravizio Bpm RCE

  • CVSS 9.9
  • Remote code execution exposure

New critical Venki Supravizio Bpm RCE (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-0066 Sap Basis

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-46310 CVSS 9.1

Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exp...

CVE-2024-46479 CVSS 9.9

Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability.

CVE-2024-5743 CVSS 9.8

An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute...

CVE-2024-57811 CVSS 9.1

In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH.

CVE-2025-0066 CVSS 9.9

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access rest...

CVE-2025-0070 CVSS 9.9

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system...

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

CVE-2025-22777 CVSS 9.8

Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a thro...

View critical disclosures

cvelogic Threat Intelligence