May 15, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-4774 Bitapps Bit Form RCE

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Bitapps Bit Form RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-0600 Codepress Visitor Statistics SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Codepress Visitor Statistics SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-30245 Judging Management System Project Judging Management System SQL Injection

  • CVSS 9.8

New critical Judging Management System Project Judging Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-0877 CVSS 9.8

Product: AndroidVersions: Android SoCAndroid ID: A-273754094

CVE-2022-4774 CVSS 9.8

The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthentica...

CVE-2022-47937 CVSS 9.8

Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-...

CVE-2023-0600 CVSS 9.8

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL quer...

CVE-2023-29861 CVSS 9.8

An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the manage...

CVE-2023-29862 CVSS 9.8

An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLev...

CVE-2023-29961 CVSS 9.8

D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,

CVE-2023-30245 CVSS 9.8

SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id p...

CVE-2023-31986 CVSS 9.8

A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the...

CVE-2023-32314 CVSS 9.8

vm2 is a sandbox that can run untrusted code with Node's built-in modules.

View critical disclosures

cvelogic Threat Intelligence