May 11, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-47129 PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.

  • CVSS 9.8
  • Remote code execution exposure

New critical Phpok RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-0854 Canon I-sensys Lbp621cw Firmware Buffer Overflow

  • CVSS 9.8

New critical Canon I-sensys Lbp621cw Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-0855 Canon I-sensys Lbp621cw Firmware Buffer Overflow

  • CVSS 9.8

New critical Canon I-sensys Lbp621cw Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-47129 CVSS 9.8

PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.

CVE-2023-0854 CVSS 9.8

Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers...

CVE-2023-0855 CVSS 9.8

Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow...

CVE-2023-0856 CVSS 9.8

Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an a...

CVE-2023-1834 CVSS 9.4

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may ha...

CVE-2023-24540 CVSS 9.8

Not all valid JavaScript whitespace characters are considered to be whitespace.

CVE-2023-29809 CVSS 9.8

SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a c...

CVE-2023-30192 CVSS 9.8

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

CVE-2023-30330 CVSS 9.8

SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_de...

View critical disclosures

cvelogic Threat Intelligence