Jun 6, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-3322 An improper neutralization of inputs used in expression language allows remote code execution wit...

  • CVSS 10
  • Remote code execution exposure

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-48780 Scshr Hr Portal Deserialization

  • CVSS 9.9

New critical Scshr Hr Portal Deserialization (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-48782 Scshr Hr Portal

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-27531 CVSS 9.8

Deserialization of Untrusted Data vulnerability in Apache InLong.

CVE-2025-3322 CVSS 10

An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.

CVE-2025-3365 CVSS 9.8

A missing protection against path traversal allows to access any file on the server.

CVE-2025-41646 CVSS 9.8

An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion.

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes M...

CVE-2025-48780 CVSS 9.9

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System throug...

CVE-2025-48782 CVSS 9.9

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management...

CVE-2025-49072 CVSS 9.8

Deserialization of Untrusted Data vulnerability in AncoraThemes Mr.

CVE-2025-49073 CVSS 9.8

Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Swe...

CVE-2025-5192 CVSS 9.3

A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System...

View critical disclosures

cvelogic Threat Intelligence