Aug 14, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • An-httpd — exploitation likelihood rose sharply (EPSS 11% → 23% · rising (+13%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Emerging exploitation risk

CVE-2002-1930 An-httpd Buffer Overflow

  • Exploitation likelihood sharply increased
  • EPSS 11% → 23% · rising (+13%)

An-httpd: EPSS 11% → 23% · rising (+13%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2025-20265 New critical Cisco Secure Firewall Management Center exposure disclosed.

  • CVSS 10
  • Network edge / SD-WAN deployments affected

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-43984 An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Versio...

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2002-1930 EPSS 11% → 23% · rising (+13%) CVSS 7.5

An-httpd Buffer Overflow

See EPSS increases

New critical disclosures

CVE-2025-20265 CVSS 10

New critical Cisco Secure Firewall Management Center exposure disclosed.

CVE-2025-27845 CVSS 9.8

In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT sec...

CVE-2025-43983 CVSS 9.1

KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_pr...

CVE-2025-43984 CVSS 9.8

An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211).

CVE-2025-50518 CVSS 9.8

A use-after-free vulnerability exists in the coap_delete_pdu_lkd function within coap_pdu.c of the libcoap library.

Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell to a Web Server....

CVE-2025-54707 CVSS 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter...

CVE-2025-7353 CVSS 9.3

A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules.

CVE-2025-8875 CVSS 9.4

N-able N-Central Insecure Deserialization

View critical disclosures

cvelogic Threat Intelligence