Jul 28, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Getgreenshot Greenshot: public exploit or PoC linked (RCE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-2636 An Gradebook Project An Gradebook SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2023-34634 Getgreenshot Greenshot RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Getgreenshot Greenshot RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2023-39015 Code4craft Webmagic

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-34634 Exploit

Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.

CVE-2023-3843 Exploit

A vulnerability was found in mooSocial mooDating 1.2.

CVE-2023-3844 Exploit

A vulnerability was found in mooSocial mooDating 1.2.

CVE-2023-3845 Exploit

A vulnerability was found in mooSocial mooDating 1.2.

CVE-2023-3846 Exploit

A vulnerability classified as problematic has been found in mooSocial mooDating 1.2.

CVE-2023-3847 Exploit

A vulnerability classified as problematic was found in mooSocial mooDating 1.2.

CVE-2023-3848 Exploit

A vulnerability, which was classified as problematic, has been found in mooSocial mooDating 1.2.

CVE-2023-3849 Exploit

A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2.

CVE-2023-2636 Exploit

The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, lea...

CVE-2023-36266 Exploit

An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions ver...

CVE-2023-29918 Exploit

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-4920 CVSS 9.6

Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specifi...

CVE-2022-4924 CVSS 9.6

Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to pot...

CVE-2023-39015 CVSS 9.8

webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.down...

CVE-2023-39016 CVSS 9.8

bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolm...

CVE-2023-39017 CVSS 9.8

quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMes...

CVE-2023-39018 CVSS 9.8

FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>.

CVE-2023-39020 CVSS 9.8

stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2Pi...

CVE-2023-39021 CVSS 9.8

wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution....

CVE-2023-39022 CVSS 9.8

oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createSt...

CVE-2023-39023 CVSS 9.8

university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.D...

View critical disclosures

cvelogic Threat Intelligence