Mar 26, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2018-25083 Pull It Project Pull It Command Injection

  • CVSS 9.8

New critical Pull It Project Pull It Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-26801 Lb-link Bl-ac1900 Firmware Command Injection

  • CVSS 9.8

New critical Lb-link Bl-ac1900 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-28883 In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.

  • CVSS 9.8

New critical Cerebrate-project Cerebrate SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-25083 CVSS 9.8

The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.

CVE-2023-26800 CVSS 9.8

Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.pat...

CVE-2023-26801 CVSS 9.8

LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a...

CVE-2023-26802 CVSS 9.8

An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass au...

CVE-2023-28883 CVSS 9.8

In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.

View critical disclosures

cvelogic Threat Intelligence