Jul 15, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Wintercms Winter: public exploit or PoC linked (XSS)

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2019-1937 Cisco Integrated Management Controller Supervisor — public exploit or PoC linked.

  • Public exploit or PoC available
  • Exploit activity linked
  • Network edge / SD-WAN deployments affected

Cisco Integrated Management Controller Supervisor privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2023-37269 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework.

  • Public exploit or PoC available
  • Exploit activity linked

Wintercms Winter XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2023-35802 Extremenetworks Iq Engine RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Extremenetworks Iq Engine RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-37269 Exploit

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework.

CVE-2022-24715 Exploit

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface.

CVE-2019-1937 Exploit

Cisco Integrated Management Controller Supervisor — public exploit or PoC linked.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-2507 CVSS 9.3

CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specia...

CVE-2023-35802 CVSS 9.8

IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be expl...

View critical disclosures

cvelogic Threat Intelligence