Jun 19, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Phpgurukul Student Study Center Management System: public exploit or PoC linked (cross-site scripting)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-33580 Phpgurukul Student Study Center Management System cross-site scripting

  • Public exploit or PoC available
  • Exploit activity linked

Phpgurukul Student Study Center Management System cross-site scripting now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2020-11027 Debian Linux

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Critical exposure

CVE-2023-27992 Zyxel Multiple NAS Devices Command Injection

  • CVSS 9.8

New critical Zyxel Multiple Network-Attached Storage (NAS) Devices Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-33580 Exploit

Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Pro...

CVE-2023-23956 Exploit

A user can supply malicious HTML and JavaScript code that will be executed in the client browser

CVE-2020-11027 Exploit

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-25736 CVSS 9.8

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior.

CVE-2023-27992 CVSS 9.8

Zyxel Multiple NAS Devices Command Injection

CVE-2023-2907 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection.

CVE-2023-29534 CVSS 9.1

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android.

CVE-2023-29542 CVSS 9.8

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such...

CVE-2023-31410 CVSS 9.8

A remote unprivileged attacker can intercept the communication via e.g.

CVE-2023-31411 CVSS 9.8

A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication.

CVE-2023-34159 CVSS 9.8

Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalatio...

CVE-2023-34416 CVSS 9.8

Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12.

View critical disclosures

cvelogic Threat Intelligence