Sep 16, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Sohamjuhin Tourism Management System: public exploit or PoC linked (RCE)
  • Powerdns Authoritative — exploitation likelihood rose sharply (EPSS 32% → 86% · rising (+54%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-43579 Debian Linux RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Debian Linux RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2023-34927 Casbin Casdoor CSRF

  • Public exploit or PoC available
  • Exploit activity linked

Casbin Casdoor CSRF now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Emerging exploitation risk

CVE-2016-5427 Powerdns Authoritative DoS

  • Exploitation likelihood sharply increased
  • EPSS 32% → 86% · rising (+54%)

Powerdns Authoritative: EPSS 32% → 86% · rising (+54%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2025-55911 Exploit

An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter

CVE-2025-55912 Exploit

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.ph...

CVE-2025-57642 Exploit

A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the...

CVE-2025-10046 Exploit

The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' p...

CVE-2025-8311 Exploit

dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint.

CVE-2025-8573 Exploit

Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.

CVE-2025-47917 Exploit

Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation.

CVE-2025-21333 Exploit

Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow

CVE-2023-34927 Exploit

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password.

CVE-2021-43579 Exploit

A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML do...

View new exploit links

Exploitation dynamics

CVE-2016-5427 EPSS 32% → 86% · rising (+54%) CVSS 7.5

Powerdns Authoritative DoS

CVE-2012-0266 EPSS 55% → 74% · rising (+18%) CVSS 9.3

Ntrglobal Ntr Activex Control Buffer Overflow

CVE-2016-4531 EPSS 6.2% → 21% · rising (+15%) CVSS 7.3

Rockwellautomation Factorytalk Energrymetrix

See EPSS increases

New critical disclosures

CVE-2024-13149 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an...

CVE-2025-34183 CVSS 9.3

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated re...

CVE-2025-34184 CVSS 9.3

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php sc...

CVE-2025-34186 CVSS 9.3

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism.

CVE-2025-34187 CVSS 9.3

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of cer...

CVE-2025-41243 CVSS 10

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification.

CVE-2025-56557 CVSS 9.1

An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol.

CVE-2025-57631 CVSS 9.8

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

CVE-2025-59334 CVSS 9.6

Linkr is a lightweight file delivery system that downloads files from a webserver.

View critical disclosures

cvelogic Threat Intelligence