Jun 6, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Cms Tree Page View Project Cms Tree Page View: public exploit or PoC linked (XSS)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-30868 Unauth.

  • Public exploit or PoC available
  • Exploit activity linked

Cms Tree Page View Project Cms Tree Page View XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2023-29632 PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.

  • CVSS 9.8

New critical Joommasters Jmspagebuilder SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-31569 Totolink X5000r Firmware Command Injection

  • CVSS 9.8

New critical Totolink X5000r Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-29632 CVSS 9.8

PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.

CVE-2023-31569 CVSS 9.8

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.

CVE-2023-32550 CVSS 9.3

Landscape's server-status page exposed sensitive system information.

CVE-2023-33532 CVSS 9.8

There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48.

CVE-2023-34409 CVSS 9.8

In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formal...

View critical disclosures

cvelogic Threat Intelligence