Home
» Risk & Exploitation
» Daily threat intelligence
» Dec 1, 2025
Dec 1, 2025 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2025-63531
Shridharshukl Blood Bank Management System SQL Injection
New critical Shridharshukl Blood Bank Management System SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2025-51682
Mjobtime privilege escalation
CVSS 9.8
Potential privilege escalation to admin/root
New critical Mjobtime privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Mjobtime SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects An...
mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to admi...
A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a...
An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges...
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component.
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component.
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component.
PublicCMS V5.202506.b is vulnerable to SSRF.
MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers.
Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local E...
View critical disclosures
cvelogic
Threat Intelligence