Jun 16, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Apple Multiple Products added to CISA KEV — confirmed in-the-wild exploitation.
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-33538 TP-Link Multiple Routers Command Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

TP-Link Multiple Routers Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-47868 Apache Nuttx Buffer Overflow

  • CVSS 9.8

New critical Apache Nuttx Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-47869 Apache Nuttx Buffer Overflow

  • CVSS 9.8

New critical Apache Nuttx Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-40916 CVSS 9.1

Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha.

CVE-2025-47868 CVSS 9.8

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion...

CVE-2025-47869 CVSS 9.8

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/x...

CVE-2025-49794 CVSS 9.1

A use-after-free vulnerability was found in libxml2.

CVE-2025-6169 CVSS 9.3

The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowing unauthenticated...

CVE-2025-6172 CVSS 9.8

Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation.

CVE-2025-6179 CVSS 9.8

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable ext...

View critical disclosures

cvelogic Threat Intelligence