Jun 18, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-46157 Efrotech Timetrax

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-20260 New critical Clamav Buffer Overflow disclosed.

  • CVSS 9.8

New critical Clamav Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-26198 Vishalmathur Cloudclassroom-php Project SQL Injection

  • CVSS 9.8

New critical Vishalmathur Cloudclassroom-php Project SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-45208 CVSS 9.8

The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service.

CVE-2025-1562 CVSS 9.8

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerab...

CVE-2025-20260 CVSS 9.8

New critical Clamav Buffer Overflow disclosed.

CVE-2025-24288 CVSS 9.8

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and m...

CVE-2025-26198 CVSS 9.8

CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component.

CVE-2025-26199 CVSS 9.8

CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability.

CVE-2025-45784 CVSS 9.8

D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive...

CVE-2025-46157 CVSS 9.9

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave req...

CVE-2025-51381 CVSS 9.3

An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier.

CVE-2025-52467 CVSS 9.1

pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications.

View critical disclosures

cvelogic Threat Intelligence