Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
4 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2025-60306Code-projects Simple Car Rental System privilege escalation
CVSS 9.9
Potential privilege escalation to admin/root
New critical Code-projects Simple Car Rental System privilege escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2025-60307Carmelo Computer Laboratory System SQL Injection
CVSS 9.8
New critical Carmelo Computer Laboratory System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2025-61929Cherry Studio is a desktop client that supports for multiple LLM providers.
CVSS 9.6
New critical disclosure (CVSS 9.6) — high severity with a short public awareness window before exploit material typically surfaces.