Nov 11, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Rockwellautomation Micrologix 1400 B Firmware — exploitation likelihood rose sharply (EPSS 15% → 37% · rising (+22%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2017-14469 Rockwellautomation Micrologix 1400 B Firmware

  • Exploitation likelihood sharply increased
  • CVSS 10
  • EPSS 15% → 37% · rising (+22%)

Rockwellautomation Micrologix 1400 B Firmware: EPSS 15% → 37% · rising (+22%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2025-12539 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Expo...

  • CVSS 10
  • Internet-facing CMS deployments affected

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2025-13032 Avast Antivirus

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2017-14469 EPSS 15% → 37% · rising (+22%) CVSS 10

Rockwellautomation Micrologix 1400 B Firmware

See EPSS increases

New critical disclosures

CVE-2017-20210 CVSS 9.8

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal rese...

CVE-2025-12539 CVSS 10

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...

CVE-2025-13021 CVSS 9.8

Incorrect boundary conditions in the Graphics: WebGPU component.

CVE-2025-13022 CVSS 9.8

Incorrect boundary conditions in the Graphics: WebGPU component.

CVE-2025-13023 CVSS 9.8

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component.

CVE-2025-13024 CVSS 9.8

JIT miscompilation in the JavaScript Engine: JIT component.

CVE-2025-13026 CVSS 9.8

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component.

CVE-2025-13032 CVSS 9.9

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overf...

CVE-2025-60724 CVSS 9.8

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2025-8324 CVSS 9.8

Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter c...

View critical disclosures

cvelogic Threat Intelligence