Jun 30, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2020-18432 Sem-cms Semcms privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Sem-cms Semcms privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-2834 Stylemixthemes Bookit Auth Bypass

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Stylemixthemes Bookit Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-3249 Miniorange Web3 - Crypto Wallet Login \& Nft Token Gating Auth Bypass

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Miniorange Web3 - Crypto Wallet Login \& Nft Token Gating Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-18432 CVSS 9.8

File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.

CVE-2023-2834 CVSS 9.8

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7.

CVE-2023-31543 CVSS 9.8

A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to th...

CVE-2023-3249 CVSS 9.8

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and incl...

CVE-2023-3490 CVSS 9.8

SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVE-2023-35175 CVSS 9.8

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Se...

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.

CVE-2023-36812 CVSS 9.8

OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB).

CVE-2023-37303 CVSS 9.8

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.

View critical disclosures

cvelogic Threat Intelligence