Apr 22, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Code-projects Online Exam Mastering System: public exploit or PoC linked (cross-site scripting)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-2745 Wordpress Directory Traversal

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2023-41425 Wondercms cross-site scripting

  • Public exploit or PoC available
  • Exploit activity linked

Wondercms cross-site scripting now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2023-44755 Mayurik Sacco Management System SQL Injection

  • CVSS 9.8

New critical Mayurik Sacco Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-28121 Exploit

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing...

CVE-2024-12905 Exploit

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path...

CVE-2024-49138 Exploit

Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow

CVE-2024-6387 Exploit

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd).

CVE-2024-4367 Exploit

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.

CVE-2024-21338 Exploit

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control

CVE-2023-41425 Exploit

Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted sc...

CVE-2023-2745 Exploit

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-44755 CVSS 9.8

Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.

CVE-2025-28035 CVSS 9.8

TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg functio...

CVE-2025-28036 CVSS 9.8

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg functi...

CVE-2025-28038 CVSS 9.8

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx func...

CVE-2025-28039 CVSS 9.8

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW funct...

CVE-2025-32965 CVSS 9.3

xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser.

CVE-2025-43946 CVSS 9.8

TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

CVE-2025-43949 CVSS 9.8

MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute maliciou...

CVE-2025-43951 CVSS 9.8

LabVantage before LV 8.8.0.13 HF6 allows local file inclusion.

View critical disclosures

cvelogic Threat Intelligence