Apr 2, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Abb Aspect-ent-12 Firmware: public exploit or PoC linked
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-22536 SAP Multiple Products HTTP Request Smuggling

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Active exploit activity

CVE-2024-6209 Abb Aspect-ent-12 Firmware

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2023-40714 Fortinet Fortisiem Path Traversal

  • CVSS 9.9

New critical Fortinet Fortisiem Path Traversal (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2024-42831 Exploit

A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary J...

CVE-2024-6209 Exploit

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacke...

CVE-2024-6298 Exploit

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacke...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-40714 CVSS 9.9

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to...

CVE-2024-38392 CVSS 9.1

Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can...

CVE-2025-0415 CVSS 9.2

A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through t...

CVE-2025-2005 CVSS 9.8

The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads...

CVE-2025-29062 CVSS 9.8

An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClie...

CVE-2025-29063 CVSS 9.8

An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set...

CVE-2025-29085 CVSS 9.8

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboar...

CVE-2025-31477 CVSS 9.3

The Tauri shell plugin allows access to the system shell.

CVE-2025-31484 CVSS 9.3

conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure.

View critical disclosures

cvelogic Threat Intelligence