Jun 8, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-2986 Tychesoftwares Abandoned Cart Lite For Woocommerce Auth Bypass

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Tychesoftwares Abandoned Cart Lite For Woocommerce Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-29402 The go command may generate unexpected code at build time when using cgo.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-29404 The go command may execute arbitrary code at build time when using cgo.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-29402 CVSS 9.8

The go command may generate unexpected code at build time when using cgo.

CVE-2023-29404 CVSS 9.8

The go command may execute arbitrary code at build time when using cgo.

CVE-2023-29405 CVSS 9.8

The go command may execute arbitrary code at build time when using cgo.

CVE-2023-2986 CVSS 9.8

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1...

CVE-2023-33443 CVSS 9.8

Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arb...

CVE-2023-34566 CVSS 9.8

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

View critical disclosures

cvelogic Threat Intelligence