May 13, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Windows: 5 CVEs added to CISA KEV today.
  • Kentico Xperience: public exploit or PoC linked (cross-site scripting)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-30400 Microsoft Windows DWM Core Library Use-After-Free

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Microsoft Windows Use-After-Free is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2024-11237 Tp-link Vn020-f3v\(t\) Firmware Buffer Overflow

  • Public exploit or PoC available
  • Exploit activity linked

Tp-link Vn020-f3v\(t\) Firmware Buffer Overflow now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-45863 Totolink A3002r Firmware Buffer Overflow

  • CVSS 9.8

New critical Totolink A3002r Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Windows Scripting Engine Type Confusion

Microsoft Windows DWM Core Library Use-After-Free

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free

Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free

View KEV additions

Exploit & PoC activity

CVE-2025-3605 Exploit

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all version...

CVE-2025-32370 Exploit

Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, bec...

CVE-2024-11237 Exploit

A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-3623 CVSS 9.1

The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deseri...

CVE-2025-43559 CVSS 9.1

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in...

CVE-2025-43560 CVSS 9.1

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in...

CVE-2025-43561 CVSS 9.1

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in ar...

CVE-2025-43562 CVSS 9.1

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Com...

CVE-2025-43563 CVSS 9.1

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in ar...

CVE-2025-43564 CVSS 9.1

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in ar...

CVE-2025-43567 CVSS 9.3

Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an a...

CVE-2025-45863 CVSS 9.8

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interf...

CVE-2025-45865 CVSS 9.8

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.

View critical disclosures

cvelogic Threat Intelligence