Apr 14, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-46880 Openbsd Libressl Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Openbsd Libressl Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-3748 Forgerock Access Management Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Forgerock Access Management Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-26463 Strongswan RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Strongswan RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-46880 CVSS 9.8

x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unve...

CVE-2022-3748 CVSS 9.8

Improper Authorization vulnerability in ForgeRock Inc.

CVE-2023-26463 CVSS 9.8

strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes...

CVE-2023-27654 CVSS 9.8

An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.

CVE-2023-29199 CVSS 9.8

There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attacke...

CVE-2023-29800 CVSS 9.8

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the Upload...

CVE-2023-29801 CVSS 9.8

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogS...

CVE-2023-29802 CVSS 9.8

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosis...

CVE-2023-29803 CVSS 9.8

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectV...

CVE-2023-29805 CVSS 9.8

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.

View critical disclosures

cvelogic Threat Intelligence