Jan 28, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-23211 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-12647 Canon Lbp1238 Ii Firmware Buffer Overflow

  • CVSS 9.8

New critical Canon Lbp1238 Ii Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-12648 Canon Lbp1238 Ii Firmware Buffer Overflow

  • CVSS 9.8

New critical Canon Lbp1238 Ii Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-3365 CVSS 9.8

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a...

CVE-2024-12647 CVSS 9.8

Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker...

CVE-2024-12648 CVSS 9.8

Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker...

CVE-2024-12649 CVSS 9.8

Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on t...

CVE-2024-13448 CVSS 9.8

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_u...

CVE-2025-23211 CVSS 9.9

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists.

CVE-2025-24480 CVSS 9.3

A Remote Code Execution Vulnerability exists in the product and version listed above.

CVE-2025-24800 CVSS 9.3

Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability.

View critical disclosures

cvelogic Threat Intelligence