May 24, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Oretnom23 Service Provider Management System: public exploit or PoC linked (SQL Injection)
  • WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-34581 Oretnom23 Service Provider Management System SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked

Oretnom23 Service Provider Management System SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2023-2732 Inspireui Mstore Api Auth Bypass

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Inspireui Mstore Api Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-2733 Inspireui Mstore Api Auth Bypass

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Inspireui Mstore Api Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-34581 Exploit

Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/vi...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-1174 CVSS 9.8

This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to t...

CVE-2023-2732 CVSS 9.8

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2.

CVE-2023-2733 CVSS 9.8

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0.

CVE-2023-2734 CVSS 9.8

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1.

CVE-2023-2868 CVSS 9.4

Barracuda Networks ESG Appliance Improper Input Validation

CVE-2023-29721 CVSS 9.8

SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.

CVE-2023-31457 CVSS 9.8

New critical Mitel Mivoice Connect exposure disclosed.

CVE-2023-31458 CVSS 9.8

New critical Mitel Mivoice Connect privilege escalation disclosed.

View critical disclosures

cvelogic Threat Intelligence