Home
» Risk & Exploitation
» Daily threat intelligence
» May 24, 2023
May 24, 2023 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Oretnom23 Service Provider Management System: public exploit or PoC linked (SQL Injection)
WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2023-34581
Oretnom23 Service Provider Management System SQL Injection
Public exploit or PoC available
Exploit activity linked
Oretnom23 Service Provider Management System SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2023-2732
Inspireui Mstore Api Auth Bypass
CVSS 9.8
Internet-facing CMS deployments affected
New critical Inspireui Mstore Api Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2023-2733
Inspireui Mstore Api Auth Bypass
CVSS 9.8
Internet-facing CMS deployments affected
New critical Inspireui Mstore Api Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploit & PoC activity
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/vi...
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to t...
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2.
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0.
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1.
Barracuda Networks ESG Appliance Improper Input Validation
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
New critical Mitel Mivoice Connect exposure disclosed.
New critical Mitel Mivoice Connect privilege escalation disclosed.
Apache RocketMQ Command Execution
New critical Netbox exposure disclosed.
View critical disclosures
cvelogic
Threat Intelligence