Jun 4, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Mailenable Enterprise — exploitation likelihood rose sharply (EPSS 9.7% → 27% · rising (+17%)).
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Emerging exploitation risk

CVE-2005-1013 Mailenable Enterprise DoS

  • Exploitation likelihood sharply increased
  • EPSS 9.7% → 27% · rising (+17%)

Mailenable Enterprise: EPSS 9.7% → 27% · rising (+17%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2021-42884 Totolink Ex1200t Firmware Command Injection

  • Exploitation likelihood sharply increased
  • CVSS 9.8
  • EPSS 6.4% → 22% · rising (+15%)

Totolink Ex1200t Firmware: EPSS 6.4% → 22% · rising (+15%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2025-5597

  • CVSS 10
  • Authentication bypass — unauthenticated access risk

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2005-1013 EPSS 9.7% → 27% · rising (+17%) CVSS 5

Mailenable Enterprise DoS

CVE-2021-42884 EPSS 6.4% → 22% · rising (+15%) CVSS 9.8

Totolink Ex1200t Firmware Command Injection

See EPSS increases

New critical disclosures

CVE-2024-13967 CVSS 9.4

This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web...

CVE-2025-20286 CVSS 9.9

New critical Cisco Identity Services Engine exposure disclosed.

CVE-2025-4578 CVSS 9.8

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via...

CVE-2025-49223 CVSS 9.8

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to exec...

CVE-2025-5597 CVSS 10

Improper Authentication vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Authentication Bypass.This issue affects airle...

CVE-2025-5598 CVSS 9.2

Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects air...

CVE-2025-5600 CVSS 9.3

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713.

View critical disclosures

cvelogic Threat Intelligence