May 19, 2025 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- Ivanti Endpoint Manager Mobile (EPMM): 2 CVEs added to CISA KEV today.
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2023-38950
ZKTeco BioTime Path Traversal
- Actively exploited (CISA KEV)
- Listed on CISA KEV
ZKTeco BioTime Path Traversal is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVE-2025-39380
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management Sys...
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2025-39401
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-managem...
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass
Ivanti Endpoint Manager Mobile (EPMM) Code Injection
Srimax Output Messenger Directory Traversal
MDaemon Email Server Cross-Site Scripting (XSS)
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS)
ZKTeco BioTime Path Traversal
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.This issue affects...
Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Object Injection.This...
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management allows Upload a...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins AnalyticsWP allows SQ...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apartment-management...
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web S...
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web S...
samlify is a Node.js library for SAML single sign-on.
Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.Thi...
View critical disclosures
cvelogic
Threat Intelligence