May 4, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-22651 Suse Rancher Privilege Escalation

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Suse Rancher Privilege Escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-23059 Geovision Gv-edge Recording Manager privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Geovision Gv-edge Recording Manager privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-30077 Judging Management System Project Judging Management System SQL Injection

  • CVSS 9.8

New critical Judging Management System Project Judging Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-20126 CVSS 9.8

New critical Cisco Spa112 Firmware exposure disclosed.

CVE-2023-22651 CVSS 9.9

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation.

CVE-2023-23059 CVSS 9.8

An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the defaul...

CVE-2023-29827 CVSS 9.8

ejs v3.1.9 is vulnerable to server-side template injection.

CVE-2023-30077 CVSS 9.8

Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, m...

CVE-2023-30203 CVSS 9.8

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_shee...

CVE-2023-30264 CVSS 9.8

CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.

CVE-2023-30268 CVSS 9.8

CLTPHP <=6.0 is vulnerable to Improper Input Validation.

CVE-2023-30328 CVSS 9.8

An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.

CVE-2023-30331 CVSS 9.8

An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.

View critical disclosures

cvelogic Threat Intelligence