Jun 1, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-22647 Suse Rancher privilege escalation

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Suse Rancher privilege escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-23952 Broadcom Advanced Secure Gateway Command Injection

  • CVSS 9.8

New critical Broadcom Advanced Secure Gateway Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-29736 Timmystudios Keyboard Themes RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Timmystudios Keyboard Themes RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-4333 CVSS 9.8

Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device.

CVE-2023-22647 CVSS 9.9

An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulat...

CVE-2023-23952 CVSS 9.8

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.

CVE-2023-29722 CVSS 9.1

The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the...

CVE-2023-29736 CVSS 9.8

Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrar...

CVE-2023-33778 CVSS 9.8

Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below...

CVE-2023-33963 CVSS 9.8

DataEase is an open source data visualization and analysis tool.

CVE-2023-33965 CVSS 9.6

Brook is a cross-platform programmable network tool.

View critical disclosures

cvelogic Threat Intelligence