Jul 22, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft SharePoint: 2 CVEs added to CISA KEV today.
  • Livehelperchat Live Helper Chat: public exploit or PoC linked (XSS)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-2775 SysAid On-Prem Improper Restriction of XML External Entity Reference

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

SysAid On-Prem XXE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2015-6176 Microsoft Edge XSS

  • Public exploit or PoC available
  • Exploit activity linked

Microsoft Edge XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-4285

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Google Chromium ANGLE and GPU Improper Input Validation

SysAid On-Prem Improper Restriction of XML External Entity Reference

SysAid On-Prem Improper Restriction of XML External Entity Reference

View KEV additions

Exploit & PoC activity

CVE-2025-51396 Exploit

A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via...

CVE-2025-51397 Exploit

A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbit...

CVE-2025-51398 Exploit

A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute...

CVE-2025-51400 Exploit

A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute a...

CVE-2025-51401 Exploit

A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arb...

CVE-2025-51403 Exploit

A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attacke...

CVE-2025-49484 Exploit

A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL c...

CVE-2025-7795 Exploit

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9.

CVE-2020-36847 Exploit

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename f...

CVE-2025-34077 Exploit

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to imp...

CVE-2023-45131 Exploit

Discourse is an open source platform for community discussion.

CVE-2015-6176 Exploit

Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protect...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-34143 CVSS 9.3

An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform.

CVE-2025-4285 CVSS 10

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies A...

CVE-2025-6187 CVSS 9.8

The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint i...

CVE-2025-6523 CVSS 9.5

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenti...

CVE-2025-8028 CVSS 9.8

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncati...

CVE-2025-8031 CVSS 9.8

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials.

CVE-2025-8037 CVSS 9.1

Setting a nameless cookie with an equals sign in the value shadowed other cookies.

CVE-2025-8038 CVSS 9.8

Thunderbird ignored paths when checking the validity of navigations in a frame.

CVE-2025-8043 CVSS 9.8

Focus incorrectly truncated URLs towards the beginning instead of around the origin.

CVE-2025-8044 CVSS 9.8

Memory safety bugs present in Firefox 140 and Thunderbird 140.

View critical disclosures

cvelogic Threat Intelligence