Jul 12, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2020-36847 Simplefilelist Simple File List RCE

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Simplefilelist Simple File List RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-36849 Ait-themes Csv Import \/ Export RCE

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Ait-themes Csv Import \/ Export RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-38036 Ivanti Avalanche RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Ivanti Avalanche RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-36847 CVSS 9.8

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename f...

CVE-2020-36849 CVSS 9.8

The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-con...

CVE-2023-38036 CVSS 9.8

A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer ov...

CVE-2025-6058 CVSS 9.8

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle(...

View critical disclosures

cvelogic Threat Intelligence