Jan 8, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-61246 Indieka900 Online Shopping System SQL Injection

  • CVSS 9.8

New critical Indieka900 Online Shopping System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-61548 Edubusinesssolutions Print Shop Pro Webdesk SQL Injection

  • CVSS 9.8

New critical Edubusinesssolutions Print Shop Pro Webdesk SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-66913 Jeecg Jimureport RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Jeecg Jimureport RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval o...

CVE-2025-61246 CVSS 9.8

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

CVE-2025-61546 CVSS 9.1

There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18...

CVE-2025-61548 CVSS 9.8

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Busine...

CVE-2025-66913 CVSS 9.8

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs.

CVE-2025-66916 CVSS 9.4

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLEx...

CVE-2025-67325 CVSS 9.8

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to ach...

CVE-2025-68715 CVSS 9.1

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform...

CVE-2025-68717 CVSS 9.4

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation.

CVE-2026-22234 CVSS 9.3

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate thr...

View critical disclosures

cvelogic Threat Intelligence