Jul 23, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Open-emr Openemr — exploitation likelihood rose sharply (EPSS 2.4% → 18% · rising (+15%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Emerging exploitation risk

CVE-2022-2494 Open-emr Openemr XSS

  • Exploitation likelihood sharply increased
  • EPSS 2.4% → 18% · rising (+15%)

Open-emr Openemr: EPSS 2.4% → 18% · rising (+15%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2025-41687 An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management...

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

High-risk exposure

CVE-2015-10141 An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and ear...

  • CVSS 9.3

New critical-severity CVE in today's window — elevated exposure signal, early in the lifecycle.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2022-2494 EPSS 2.4% → 18% · rising (+15%) CVSS 5.4

Open-emr Openemr XSS

See EPSS increases

New critical disclosures

CVE-2015-10141 CVSS 9.3

An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension develope...

CVE-2016-15044 CVSS 9.3

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data...

CVE-2017-20198 CVSS 9.3

The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers.

CVE-2018-25114 CVSS 9.3

A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and...

CVE-2022-4978 CVSS 9.3

Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, w...

CVE-2025-40599 CVSS 9.1

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface.

CVE-2025-41687 CVSS 9.8

An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected...

CVE-2025-54294 CVSS 9.3

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered.

CVE-2025-54455 CVSS 9.1

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects Mag...

CVE-2025-8070 CVSS 9.2

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability.

View critical disclosures

cvelogic Threat Intelligence