Apr 8, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Windows added to CISA KEV — confirmed in-the-wild exploitation.
  • Sony Xav-ax5500 Firmware: public exploit or PoC linked (RCE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-29824 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Microsoft Windows Use-After-Free is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2019-15949 Nagios XI Remote Code Execution

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Nagios XI RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-32028 HAX CMS PHP allows you to manage your microsite universe with PHP backend.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free

Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key

View KEV additions

Exploit & PoC activity

CVE-2024-56902 Exploit

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account...

CVE-2024-30896 Exploit

InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users wit...

CVE-2024-23922 Exploit

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability.

CVE-2020-7656 Exploit

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.

CVE-2019-11358 Exploit

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.proto...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-48887 CVSS 9.8

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwo...

CVE-2025-22871 CVSS 9.1

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines.

CVE-2025-24446 CVSS 9.1

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in...

CVE-2025-24447 CVSS 9.1

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could res...

CVE-2025-25226 CVSS 9.8

Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package.

CVE-2025-30281 CVSS 9.1

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in ar...

CVE-2025-30282 CVSS 9.1

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in ar...

CVE-2025-32020 CVSS 9.3

The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries.

CVE-2025-32028 CVSS 9.9

HAX CMS PHP allows you to manage your microsite universe with PHP backend.

CVE-2025-32461 CVSS 9.9

wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.

View critical disclosures

cvelogic Threat Intelligence