Jan 29, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Apple Multiple Products added to CISA KEV — confirmed in-the-wild exploitation.
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-24085 Apple Multiple Products Use-After-Free

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Apple Multiple Products Use-After-Free is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-21415 Microsoft Azure Ai Face Service Auth Bypass

  • CVSS 9.9
  • Authentication bypass — unauthenticated access risk

New critical Microsoft Azure Ai Face Service Auth Bypass (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-57665 JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java.

  • CVSS 9.8

New critical Heyewei Jfinalcms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-54852 CVSS 9.8

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injec...

CVE-2024-57395 CVSS 9.8

Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbit...

CVE-2024-57665 CVSS 9.8

JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java.

CVE-2025-0851 CVSS 9.3

A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files...

CVE-2025-20014 CVSS 9.3

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information.

CVE-2025-20061 CVSS 9.3

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information.

CVE-2025-21415 CVSS 9.9

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

View critical disclosures

cvelogic Threat Intelligence