Apr 6, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Reservit Hotel: public exploit or PoC linked (XSS)

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2024-48827 Sbond Watcharr privilege escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Sbond Watcharr privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2024-8856 Revmakx Backup And Staging By Wp Time Capsule RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

High-risk exposure

CVE-2025-32013 LNbits is a Lightning wallet and accounts system.

  • CVSS 9.3

New high-severity Lnbits SSRF — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2024-9458 Exploit

The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users...

CVE-2024-8856 Exploit

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...

CVE-2024-48827 Exploit

An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password...

CVE-2024-5910 Exploit

Palo Alto Networks Expedition Missing Authentication

CVE-2024-30269 Exploit

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to v...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-32013 CVSS 9.3

LNbits is a Lightning wallet and accounts system.

View critical disclosures

cvelogic Threat Intelligence