Mar 20, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Joomlaux Jux Real Estate: public exploit or PoC linked (SQL Injection)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2025-2126 A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical.

  • Public exploit or PoC available
  • Exploit activity linked

Joomlaux Jux Real Estate SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-26852 DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

  • CVSS 10

New critical Descor Infocad SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-26853 DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical Descor Infocad privilege escalation (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-2126 Exploit

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-48590 CVSS 9.8

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService.

CVE-2024-9309 CVSS 9.3

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server i...

CVE-2024-9701 CVSS 9.8

A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8).

CVE-2025-2311 CVSS 9

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in...

CVE-2025-2538 CVSS 9.8

A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may...

CVE-2025-26852 CVSS 10

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

CVE-2025-26853 CVSS 10

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

CVE-2025-29411 CVSS 9.8

An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execut...

CVE-2025-29922 CVSS 9.6

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads.

CVE-2025-29980 CVSS 9.3

A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77.

View critical disclosures

cvelogic Threat Intelligence