Mar 13, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-45423 A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c..

  • CVSS 9.8

New critical Pev Project Pev Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-0037 10web Map Builder For Google Maps SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical 10web Map Builder For Google Maps SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-25207 PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

  • CVSS 9.8

New critical Prestashop Dpd France SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-45423 CVSS 9.8

A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c..

CVE-2023-0037 CVSS 9.8

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using t...

CVE-2023-0345 CVSS 9.8

The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user.

CVE-2023-0352 CVSS 9.1

The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file.

CVE-2023-0354 CVSS 9.1

The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive informati...

CVE-2023-25207 CVSS 9.8

PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

CVE-2023-25279 CVSS 9.8

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.

CVE-2023-27052 CVSS 9.8

E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php.

CVE-2023-27582 CVSS 9.1

maddy is a composable, all-in-one mail server.

View critical disclosures

cvelogic Threat Intelligence