Apr 7, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • CrushFTP added to CISA KEV — confirmed in-the-wild exploitation.
  • Yeswiki: public exploit or PoC linked (Path Traversal)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-31161 CrushFTP Authentication Bypass

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Authentication bypass — unauthenticated access risk

CrushFTP Auth Bypass is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2025-24813 Apache Tomcat Path Equivalence

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Apache Tomcat RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-20654 In wlan service, there is a possible out of bounds write due to an incorrect bounds check.

  • CVSS 9.8
  • Remote code execution exposure

New critical Mediatek Mt6890 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-20654 CVSS 9.8

In wlan service, there is a possible out of bounds write due to an incorrect bounds check.

CVE-2025-28402 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

CVE-2025-28405 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

CVE-2025-28406 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

CVE-2025-28408 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} e...

CVE-2025-28410 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whe...

CVE-2025-28411 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

CVE-2025-28412 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

CVE-2025-28413 CVSS 9.8

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

View critical disclosures

cvelogic Threat Intelligence