Jul 19, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Citrix NetScaler ADC And NetScaler Gateway added to CISA KEV — confirmed in-the-wild exploitation.
  • Simple Online Piggery Management System Project Simple Online Piggery Management System: public exploit or PoC linked
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-3519 Citrix NetScaler ADC and NetScaler Gateway Code Injection

  • Actively exploited (CISA KEV)
  • CVSS 9.8
  • Listed on CISA KEV
  • Remote code execution exposure

Citrix NetScaler ADC And NetScaler Gateway RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2022-28171 Hikvision Ds-a71024 Firmware

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2023-38408 Fedoraproject Fedora RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Fedoraproject Fedora RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

CVE-2023-3519 KEV CVSS 9.8

Citrix NetScaler ADC and NetScaler Gateway Code Injection

View KEV additions

Exploit & PoC activity

CVE-2023-37629 Exploit

Online Piggery Management System 1.0 is vulnerable to File Upload.

CVE-2023-1258 Exploit

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service...

CVE-2022-28171 Exploit

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-30799 CVSS 9.1

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue.

CVE-2023-34034 CVSS 9.1

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and S...

CVE-2023-3638 CVSS 9.8

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

CVE-2023-37289 CVSS 9.8

It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On...

CVE-2023-38408 CVSS 9.8

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution...

View critical disclosures

cvelogic Threat Intelligence