Jan 31, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-53356 Easyvirt Co2scope Privilege Escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Easyvirt Co2scope Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-53584 Openpanel Command Injection

  • CVSS 9.8

New critical Openpanel Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-22957 Zzcms SQL Injection

  • CVSS 9.8

New critical Zzcms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-47857 CVSS 9.8

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native...

CVE-2024-53320 CVSS 9.8

Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadP...

CVE-2024-53356 CVSS 9.8

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege e...

CVE-2024-53537 CVSS 9.1

An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

CVE-2024-53584 CVSS 9.8

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

CVE-2024-55062 CVSS 9.8

Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitr...

CVE-2024-57587 CVSS 9.1

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to exec...

CVE-2025-22957 CVSS 9.8

A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication.

CVE-2025-23215 CVSS 9.3

PMD is an extensible multilanguage static code analyzer.

View critical disclosures

cvelogic Threat Intelligence