Feb 23, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-2504 Sdd-baro Project Sdd-baro SQL Injection

  • CVSS 9.8

New critical Sdd-baro Project Sdd-baro SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-24205 Clash Project Clash RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Clash Project Clash RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-26326 Themekraft Buddyforms Deserialization

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Themekraft Buddyforms Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-2504 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allo...

CVE-2022-36231 CVSS 9.8

pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

CVE-2023-0754 CVSS 9.8

The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely...

CVE-2023-0755 CVSS 9.8

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remo...

CVE-2023-23914 CVSS 9.1

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when mul...

CVE-2023-24104 CVSS 9.8

Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.

CVE-2023-24205 CVSS 9.8

Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the c...

CVE-2023-24212 CVSS 9.8

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.

CVE-2023-26326 CVSS 9.8

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue.

CVE-2023-26468 CVSS 9.1

Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.

View critical disclosures

cvelogic Threat Intelligence