Jan 30, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-12822 Userproplugin Media Manager Privilege Escalation

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Userproplugin Media Manager Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-13742 Icontrolwp Deserialization

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Icontrolwp Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-1736 Canonical Gnome-remote-desktop

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1736 CVSS 9.8

Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

CVE-2024-12248 CVSS 9.3

Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted...

CVE-2024-12822 CVSS 9.8

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati...

CVE-2024-13742 CVSS 9.8

The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in...

CVE-2025-0477 CVSS 9.3

An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre.

CVE-2025-0680 CVSS 9.3

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take cont...

CVE-2025-24503 CVSS 9.3

A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.

View critical disclosures

cvelogic Threat Intelligence