Aug 3, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Tesigandia Gandia Integra Total: public exploit or PoC linked (SQL Injection)
  • Lacaveprods Intellitamper — exploitation likelihood rose sharply (EPSS 12% → 24% · rising (+12%)).

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2025-41373 Tesigandia Gandia Integra Total SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked

Tesigandia Gandia Integra Total SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2025-54589 Copyparty is a portable file server.

  • Public exploit or PoC available
  • Exploit activity linked

9001 Copyparty XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Emerging exploitation risk

CVE-2006-2494 Lacaveprods Intellitamper Buffer Overflow

  • Exploitation likelihood sharply increased
  • EPSS 12% → 24% · rising (+12%)

Lacaveprods Intellitamper: EPSS 12% → 24% · rising (+12%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-41373 Exploit

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1.

CVE-2025-54769 Exploit

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of th...

CVE-2025-8191 Exploit

A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3.

CVE-2025-49683 Exploit

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.

CVE-2025-49741 Exploit

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2023-3460 Exploit

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effe...

View new exploit links

Exploitation dynamics

CVE-2006-2494 EPSS 12% → 24% · rising (+12%) CVSS 5.1

Lacaveprods Intellitamper Buffer Overflow

See EPSS increases

New critical disclosures

Nothing flagged in this category for this digest.

View critical disclosures

cvelogic Threat Intelligence