Nov 10, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Samsung Mobile Devices added to CISA KEV — confirmed in-the-wild exploitation.
  • WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-21042 Samsung Mobile Devices Out-of-Bounds Write

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Samsung Mobile Devices Out-of-Bounds Write is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-42890 SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or function...

  • CVSS 10
  • Remote code execution exposure

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-42887 Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert...

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-4462 CVSS 9.3

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to u...

CVE-2025-11170 CVSS 9.8

The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Imp...

CVE-2025-11457 CVSS 9.8

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in...

CVE-2025-12813 CVSS 9.8

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via...

CVE-2025-42887 CVSS 9.9

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-ena...

CVE-2025-42890 CVSS 10

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing...

CVE-2025-64513 CVSS 9.3

Milvus is an open-source vector database built for generative AI applications.

CVE-2025-64522 CVSS 9.1

Soft Serve is a self-hostable Git server for the command line.

View critical disclosures

cvelogic Threat Intelligence