Home
» Risk & Exploitation
» Daily threat intelligence
» Jun 29, 2023
Jun 29, 2023 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Samsung Mobile Devices: 6 CVEs added to CISA KEV today.
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2019-20500
D-Link DWL-2600AP Access Point Command Injection
Actively exploited (CISA KEV)
Listed on CISA KEV
D-Link DWL-2600AP Access Point Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVSS 9.9
Remote code execution exposure
New critical Xwiki RCE (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVSS 9.9
Remote code execution exposure
New critical Xwiki RCE (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Samsung Mobile Devices Out-of-Bounds Read
Samsung Mobile Devices Improper Input Validation
Samsung Mobile Devices Race Condition
Samsung Mobile Devices Race Condition
Samsung Mobile Devices Unspecified
Samsung Mobile Devices Improper Boundary Check
D-Link DWL-2600AP Access Point Command Injection
D-Link DIR-859 Router Command Execution
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
An issue was discovered in Weblib Ucopia before 6.0.13.
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windo...
Sealos is an open source cloud operating system distribution based on the Kubernetes kernel.
STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and...
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
Xwiki commons is the common modules used by other XWiki top level projects.
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
View critical disclosures
cvelogic
Threat Intelligence