Jul 16, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Pivotx: public exploit or PoC linked (cross-site scripting)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2024-11605 Wp-publications Project Wp-publications XSS

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2025-1550 Keras RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Keras RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-20337 Cisco Identity Services Engine Injection

  • CVSS 10
  • Network edge / SD-WAN deployments affected

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-52367 Exploit

Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.

CVE-2025-27210 Exploit

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX.

CVE-2024-58258 Exploit

SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

CVE-2025-52089 Exploit

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to...

CVE-2025-44177 Exploit

A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ e...

CVE-2025-49677 Exploit

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2025-49744 Exploit

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2025-6563 Exploit

A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2.

CVE-2025-1550 Exploit

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious...

CVE-2024-11605 Exploit

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow hig...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-34117 CVSS 9.3

A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due...

CVE-2025-34121 CVSS 9.3

An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2.

CVE-2025-34125 CVSS 9.3

An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1...

CVE-2025-34127 CVSS 9.3

A stack-based buffer overflow exists in Achat v0.150 in its default configuration.

CVE-2025-34132 CVSS 9.3

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the...

CVE-2025-34300 CVSS 10

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciw...

CVE-2025-53937 CVSS 9.4

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions.

CVE-2025-5396 CVSS 9.8

The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0.

CVE-2025-7712 CVSS 9.1

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_...

View critical disclosures

cvelogic Threat Intelligence