Jun 14, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Pyload: public exploit or PoC linked
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-0297 Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2023-34251 Grav is a flat-file content management system.

  • CVSS 9.9
  • Remote code execution exposure

New critical Getgrav Grav RCE (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-1329 A potential security vulnerability has been identified for certain HP multifunction printers (MFPs).

  • CVSS 9.8
  • Remote code execution exposure

New critical Hp Laserjet Managed Mfp E62665 3gy14a Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-0297 Exploit

Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-1329 CVSS 9.8

A potential security vulnerability has been identified for certain HP multifunction printers (MFPs).

CVE-2023-25367 CVSS 9.8

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or...

CVE-2023-30150 CVSS 9.8

PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

CVE-2023-31671 CVSS 9.8

PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

CVE-2023-31746 CVSS 9.8

There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0.

CVE-2023-34095 CVSS 9.8

cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project.

CVE-2023-34251 CVSS 9.9

Grav is a flat-file content management system.

CVE-2023-34540 CVSS 9.8

Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the...

CVE-2023-34756 CVSS 9.8

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=char...

CVE-2023-34865 CVSS 9.8

Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.

View critical disclosures

cvelogic Threat Intelligence