May 29, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Campcodes Online Hospital Management System: public exploit or PoC linked (SQL Injection)
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2024-0204 Fortra Goanywhere Managed File Transfer Auth Bypass

  • Public exploit or PoC available
  • Exploit activity linked
  • Authentication bypass — unauthenticated access risk

Fortra Goanywhere Managed File Transfer Auth Bypass now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2024-28995 SolarWinds Serv-U Path Traversal

  • Public exploit or PoC available
  • Exploit activity linked

SolarWinds Serv-U Path Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-48748 Netwrix Directory Manager

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-5298 Exploit

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0.

CVE-2025-4094 Exploit

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making...

CVE-2025-4971 Exploit

Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on th...

CVE-2025-24071 Exploit

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing o...

CVE-2024-0204 Exploit

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administratio...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-41591 CVSS 9.8

An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-mid...

CVE-2025-30466 CVSS 9.8

This issue was addressed through improved state management.

CVE-2025-31263 CVSS 9.1

The issue was addressed with improved memory handling.

CVE-2025-3755 CVSS 9.1

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series...

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

CVE-2025-48047 CVSS 9.4

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php end...

CVE-2025-48336 CVSS 9.8

Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This issue affects Cou...

CVE-2025-48748 CVSS 10

Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.

CVE-2025-4967 CVSS 9.1

Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.

View critical disclosures

cvelogic Threat Intelligence