Jan 24, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • SonicWall SMA1000 Appliances added to CISA KEV — confirmed in-the-wild exploitation.
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-23006 SonicWall SMA1000 Appliances Deserialization

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

SonicWall SMA1000 Appliances Deserialization is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-22609 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical Coollabs Coolify privilege escalation (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-22612 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical Coollabs Coolify privilege escalation (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-13545 CVSS 9.8

The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path...

CVE-2024-50694 CVSS 9.8

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does n...

CVE-2024-50695 CVSS 9.8

SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT messages, due to miss...

CVE-2024-50698 CVSS 9.8

SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message...

CVE-2024-56404 CVSS 9.9

In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation.

CVE-2025-22609 CVSS 10

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-22611 CVSS 9.9

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-22612 CVSS 10

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.

CVE-2025-24650 CVSS 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a Web Server.This...

View critical disclosures

cvelogic Threat Intelligence