Aug 18, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Trend Micro Apex One added to CISA KEV — confirmed in-the-wild exploitation.
  • Tenda Ac20 Firmware: public exploit or PoC linked (Command Injection)
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-54948 Trend Micro Apex One OS Command Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Trend Micro Apex One Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2024-28623 Ritecms XSS

  • Public exploit or PoC available
  • Exploit activity linked

Ritecms XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2025-55591 Totolink A3002r Firmware Command Injection

  • CVSS 9.8

New critical Totolink A3002r Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

CVE-2025-9090 Exploit

A vulnerability was identified in Tenda AC20 16.03.08.12.

CVE-2025-52392 Exploit

Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms.

CVE-2025-50154 Exploit

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing o...

CVE-2025-7766 Exploit

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading t...

CVE-2024-54761 Exploit

BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

CVE-2024-28623 Exploit

RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

CVE-2015-6830 Exploit

libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attacke...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

CVE-2025-54156 CVSS 9.1

The Sante PACS Server Web Portal sends credential information without encryption.

Capsule is a multi-tenancy and policy-based framework for Kubernetes.

CVE-2025-55282 CVSS 9.1

aiven-db-migrate is an Aiven database migration tool.

CVE-2025-55283 CVSS 9.1

aiven-db-migrate is an Aiven database migration tool.

CVE-2025-55293 CVSS 9.4

Meshtastic is an open source mesh networking solution.

CVE-2025-55299 CVSS 9.4

VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates.

CVE-2025-55591 CVSS 9.8

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formM...

CVE-2025-7693 CVSS 9.3

A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing.

View critical disclosures

cvelogic Threat Intelligence