Apr 7, 2025 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- CrushFTP added to CISA KEV — confirmed in-the-wild exploitation.
- Yeswiki: public exploit or PoC linked (Path Traversal)
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2025-31161
CrushFTP Authentication Bypass
- Actively exploited (CISA KEV)
- Listed on CISA KEV
- Authentication bypass — unauthenticated access risk
CrushFTP Auth Bypass is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Active exploit activity
CVE-2025-24813
Apache Tomcat Path Equivalence
- Public exploit or PoC available
- Exploit activity linked
- Remote code execution exposure
Apache Tomcat RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2025-20654
In wlan service, there is a possible out of bounds write due to an incorrect bounds check.
- CVSS 9.8
- Remote code execution exposure
New critical Mediatek Mt6890 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
CrushFTP Authentication Bypass
View KEV additions
Exploit & PoC activity
YesWiki is a wiki system written in PHP.
Apache Tomcat Path Equivalence
XWiki Platform Eval Injection
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
In wlan service, there is a possible out of bounds write due to an incorrect bounds check.
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} e...
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whe...
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
Langflow Missing Authentication
View critical disclosures
cvelogic
Threat Intelligence