May 18, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-2024 Johnsoncontrols Openblue Enterprise Manager Data Collector

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-2704 Vibethemes Bp Social Connect Auth Bypass

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Vibethemes Bp Social Connect Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-28081 Facebook Hermes RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Facebook Hermes RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-2024 CVSS 10

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user und...

CVE-2023-23556 CVSS 9.8

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a mali...

CVE-2023-23557 CVSS 9.8

An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a...

CVE-2023-25933 CVSS 9.8

A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker...

CVE-2023-2704 CVSS 9.8

The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5.

CVE-2023-28081 CVSS 9.8

A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free a...

CVE-2023-28753 CVSS 9.8

netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function.

CVE-2023-30333 CVSS 9.8

An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arb...

CVE-2023-30470 CVSS 9.8

A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990...

View critical disclosures

cvelogic Threat Intelligence