Jan 15, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Kde Kmplayer — exploitation likelihood rose sharply (EPSS 6.6% → 21% · rising (+14%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Emerging exploitation risk

CVE-2009-2896 Kde Kmplayer Buffer Overflow

  • Exploitation likelihood sharply increased
  • CVSS 9.3
  • EPSS 6.6% → 21% · rising (+14%)

Kde Kmplayer: EPSS 6.6% → 21% · rising (+14%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2025-70892 Phpgurukul Cyber Cafe Management System SQL Injection

  • CVSS 9.8

New critical Phpgurukul Cyber Cafe Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-67079 Agora-project

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2009-2896 EPSS 6.6% → 21% · rising (+14%) CVSS 9.3

Kde Kmplayer Buffer Overflow

See EPSS increases

New critical disclosures

CVE-2011-10041 CVSS 9.3

Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to m...

CVE-2023-7334 CVSS 9.3

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to rem...

CVE-2025-62193 CVSS 9.3

Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFe...

CVE-2025-67079 CVSS 9.8

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagic...

CVE-2025-67822 CVSS 9.4

New critical Mitel Mivoice Mx-one Auth Bypass disclosed.

CVE-2025-70892 CVSS 9.8

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module.

CVE-2026-1009 CVSS 9

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post...

CVE-2026-22863 CVSS 9.2

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

CVE-2026-23746 CVSS 9.3

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prio...

View critical disclosures

cvelogic Threat Intelligence