Jan 23, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • JQuery added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2020-11023 JQuery Cross-Site Scripting (XSS)

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

JQuery XSS is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-57328 A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0.

  • CVSS 9.8

New critical Projectworlds Online Food Ordering System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-46400 KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-46400 CVSS 9.8

KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.

CVE-2023-46401 CVSS 9.8

KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.

CVE-2024-52329 CVSS 9.5

ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates.

CVE-2024-52330 CVSS 9.5

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates.

CVE-2024-53923 CVSS 9.1

An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24.

CVE-2024-55192 CVSS 9.8

OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char c...

CVE-2024-55193 CVSS 9.8

OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.

CVE-2024-55194 CVSS 9.8

OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.

CVE-2024-55573 CVSS 9.1

An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before...

CVE-2024-57328 CVSS 9.8

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0.

View critical disclosures

cvelogic Threat Intelligence