Jun 9, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Thruk: public exploit or PoC linked (Path Traversal)

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-34096 Thruk Path Traversal

  • Public exploit or PoC available
  • Exploit activity linked

Thruk Path Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2021-24499 Amentotech Workreap

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Critical exposure

CVE-2023-34364 Progress Datadirect Odbc Oracle Wire Protocol Driver Buffer Overflow

  • CVSS 9.8

New critical Progress Datadirect Odbc Oracle Wire Protocol Driver Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-34096 Exploit

Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends.

CVE-2021-24499 Exploit

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-34364 CVSS 9.8

A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle.

View critical disclosures

cvelogic Threat Intelligence