Mar 22, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Teampass: public exploit or PoC linked (SQL Injection)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-1545 SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

  • Public exploit or PoC available
  • Exploit activity linked

Teampass SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2024-21320 Windows Themes Spoofing Vulnerability

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

High-risk exposure

CVE-2025-2618 A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03.

  • CVSS 9.3

New high-severity Dlink Dap-1620 Firmware Buffer Overflow — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-1545 Exploit

SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-2618 CVSS 9.3

A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03.

CVE-2025-2619 CVSS 9.3

A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03.

CVE-2025-2620 CVSS 9.3

A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical.

CVE-2025-2621 CVSS 9.3

A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical.

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_toke...

View critical disclosures

cvelogic Threat Intelligence