Jul 25, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Ivanti Endpoint Manager Mobile (EPMM) added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-35078 Ivanti Endpoint Manager Mobile Authentication Bypass

  • Actively exploited (CISA KEV)
  • CVSS 9.8
  • Listed on CISA KEV
  • Authentication bypass — unauthenticated access risk

Ivanti Endpoint Manager Mobile (EPMM) Auth Bypass is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-46898 An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8.

  • CVSS 9.8

New critical Vocera Report Server Path Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-35066 Infodrom E-invoice Approval System SQL Injection

  • CVSS 9.8

New critical Infodrom E-invoice Approval System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

CVE-2023-35078 KEV CVSS 9.8

Ivanti Endpoint Manager Mobile Authentication Bypass

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-46898 CVSS 9.8

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8.

CVE-2023-34798 CVSS 9.8

An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2023-35066 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approva...

CVE-2023-35088 CVSS 9.8

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache I...

CVE-2023-35980 CVSS 9.8

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sen...

CVE-2023-35981 CVSS 9.8

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sen...

CVE-2023-35982 CVSS 9.8

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sen...

CVE-2023-37677 CVSS 9.8

Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_edit...

CVE-2023-37895 CVSS 9.8

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersio...

View critical disclosures

cvelogic Threat Intelligence