Dec 1, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-63531 Shridharshukl Blood Bank Management System SQL Injection

  • CVSS 10

New critical Shridharshukl Blood Bank Management System SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-51682 Mjobtime privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Mjobtime privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-51683 Mjobtime SQL Injection

  • CVSS 9.8

New critical Mjobtime SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-3500 CVSS 9

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects An...

CVE-2025-51682 CVSS 9.8

mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to admi...

CVE-2025-51683 CVSS 9.8

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a...

CVE-2025-63525 CVSS 9.6

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges...

CVE-2025-63531 CVSS 10

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component.

CVE-2025-63532 CVSS 9.6

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component.

CVE-2025-63535 CVSS 9.6

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component.

CVE-2025-65836 CVSS 9.1

PublicCMS V5.202506.b is vulnerable to SSRF.

CVE-2025-66401 CVSS 9.8

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers.

CVE-2025-8351 CVSS 9

Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local E...

View critical disclosures

cvelogic Threat Intelligence