Dec 8, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Array Networks ArrayOS AG added to CISA KEV — confirmed in-the-wild exploitation.
  • Pluck-cms Pluck: public exploit or PoC linked
  • Apache Dolphinscheduler — exploitation likelihood rose sharply (EPSS 7.3% → 21% · rising (+14%)).
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-37055 D-Link Routers Buffer Overflow

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

D-Link Routers Buffer Overflow is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2018-11736 An issue was discovered in Pluck before 4.7.7-dev2.

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2022-45462 Apache Dolphinscheduler Command Injection

  • Exploitation likelihood sharply increased
  • CVSS 9.8
  • EPSS 7.3% → 21% · rising (+14%)

Apache Dolphinscheduler: EPSS 7.3% → 21% · rising (+14%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

CVE-2018-11736 Exploit

An issue was discovered in Pluck before 4.7.7-dev2.

View new exploit links

Exploitation dynamics

CVE-2022-45462 EPSS 7.3% → 21% · rising (+14%) CVSS 9.8

Apache Dolphinscheduler Command Injection

CVE-2008-1809 EPSS 23% → 33% · rising (+10%) CVSS 10

Novell Edirectory Buffer Overflow

See EPSS increases

New critical disclosures

CVE-2025-27019 CVSS 9.8

Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain sy...

CVE-2025-27020 CVSS 9.8

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access d...

CVE-2025-48626 CVSS 9.8

In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure.

CVE-2025-61318 CVSS 9.1

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.

CVE-2025-64081 CVSS 9.8

SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows at...

CVE-2025-65548 CVSS 9.1

NUT-14 allows cashu tokens to be created with a preimage hash.

CVE-2025-65849 CVSS 9.1

A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of...

View critical disclosures

cvelogic Threat Intelligence