Mar 18, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Tj-actions Changed-files GitHub Action added to CISA KEV — confirmed in-the-wild exploitation.
  • Chamilo Lms: public exploit or PoC linked (RCE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-24472 Fortinet FortiOS and FortiProxy Authentication Bypass

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Authentication bypass — unauthenticated access risk

Fortinet FortiOS And FortiProxy Auth Bypass is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2023-4220 Chamilo Lms RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Chamilo Lms RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2024-10442 Syncology Replication Service

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

tj-actions/changed-files GitHub Action Embedded Malicious Code

Fortinet FortiOS and FortiProxy Authentication Bypass

View KEV additions

Exploit & PoC activity

CVE-2023-4220 Exploit

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1....

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-10441 CVSS 9.8

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Sy...

CVE-2024-10442 CVSS 10

Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-042...

CVE-2024-11131 CVSS 9.8

A vulnerability regarding out-of-bounds read is found in the video interface.

CVE-2024-56346 CVSS 10

IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

CVE-2024-56347 CVSS 9.6

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improp...

CVE-2024-57169 CVSS 9.8

A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php.

CVE-2025-25595 CVSS 9.8

A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.

CVE-2025-30132 CVSS 9.1

An issue was discovered on IROAD Dashcam V devices.

CVE-2025-30137 CVSS 9.8

An issue was discovered in the G-Net GNET APK 2.6.2.

CVE-2025-30139 CVSS 9.8

An issue was discovered on G-Net Dashcam BB GONX devices.

View critical disclosures

cvelogic Threat Intelligence