May 30, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-47526 Fox-it Fox Datadiode Firmware RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Fox-it Fox Datadiode Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-29727 Applika Call Blocker privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Applika Call Blocker privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-29728 Applika Call Blocker privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Applika Call Blocker privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-47526 CVSS 9.8

Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files.

CVE-2023-28347 CVSS 9.6

An issue was discovered in Faronics Insight 10.0.19045 on Windows.

CVE-2023-29727 CVSS 9.8

The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its da...

CVE-2023-29728 CVSS 9.8

The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of p...

CVE-2023-29734 CVSS 9.8

An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the...

CVE-2023-29739 CVSS 9.8

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by...

CVE-2023-29741 CVSS 9.8

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating th...

CVE-2023-2987 CVSS 9.8

The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on...

CVE-2023-33734 CVSS 9.8

BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.

View critical disclosures

cvelogic Threat Intelligence