2024年1月4日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2023-50864 Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

  • CVSS 9.8

新たな重大 Kashipara Travel Website SQL Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2023-50865 Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

  • CVSS 9.8

新たな重大 Kashipara Travel Website SQL Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2023-50866 Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

  • CVSS 9.8

新たな重大 Kashipara Travel Website SQL Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2023-50864 CVSS 9.8

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-50865 CVSS 9.8

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-50866 CVSS 9.8

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-50867 CVSS 9.8

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-51154 CVSS 9.8

Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

CVE-2023-51812 CVSS 9.8

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetCont...

CVE-2024-22051 CVSS 9.8

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability.

CVE-2024-22086 CVSS 9.8

handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code execu...

CVE-2024-22087 CVSS 9.8

route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote cod...

CVE-2024-22088 CVSS 9.8

Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mish...

Critical 公開を見る

cvelogic Threat Intelligence