May 30, 2023 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2022-47526
Fox-it Fox Datadiode Firmware RCE
- CVSS 9.8
- Remote code execution exposure
New critical Fox-it Fox Datadiode Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2023-29727
Applika Call Blocker privilege escalation
- CVSS 9.8
- Potential privilege escalation to admin/root
New critical Applika Call Blocker privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2023-29728
Applika Call Blocker privilege escalation
- CVSS 9.8
- Potential privilege escalation to admin/root
New critical Applika Call Blocker privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files.
An issue was discovered in Faronics Insight 10.0.19045 on Windows.
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its da...
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of p...
An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the...
An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by...
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating th...
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on...
BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.
A vulnerability was found in ImageMagick.
View critical disclosures
cvelogic
Threat Intelligence