Critical exposure
CVE-2022-23848 In Alluxio before 2.7.3, the logserver does not validate the input stream.
- CVSS 9.8
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
High-risk exposure
New high-severity Url-parse Project Url-parse privilege escalation — watch for exploit drops and scanner noise in the first 72 hours after disclosure.
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
In Alluxio before 2.7.3, the logserver does not validate the input stream.