May 8, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-2583 Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-28201 This issue was addressed with improved state management.

  • CVSS 9.8
  • Remote code execution exposure

New critical Apple Ipados RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-30092 Online Pizza Ordering System Project Online Pizza Ordering System SQL Injection

  • CVSS 9.8

New critical Online Pizza Ordering System Project Online Pizza Ordering System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-23526 CVSS 9.8

This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder.

CVE-2023-2478 CVSS 9.6

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 be...

CVE-2023-2583 CVSS 10

Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.

CVE-2023-27953 CVSS 9.8

The issue was addressed with improved memory handling.

CVE-2023-27958 CVSS 9.1

The issue was addressed with improved memory handling.

CVE-2023-28201 CVSS 9.8

This issue was addressed with improved state management.

CVE-2023-29696 CVSS 9.8

H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set.

CVE-2023-30092 CVSS 9.8

SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.

CVE-2023-31123 CVSS 9.1

`effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports.

libspdm is a sample implementation that follows the DMTF SPDM specifications.

View critical disclosures

cvelogic Threat Intelligence