Aug 4, 2023 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- Campcodes Complete Online Matrimonial Website System Script: public exploit or PoC linked (cross-site scripting)
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2023-2796
Myeventon Eventon privilege escalation
- Public exploit or PoC available
- Exploit activity linked
- Internet-facing CMS deployments affected
WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.
Active exploit activity
CVE-2023-33383
Shelly Pro 4pm Firmware memory safety
- Public exploit or PoC available
- Exploit activity linked
Shelly Pro 4pm Firmware memory safety now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2023-39344
social-media-skeleton is an uncompleted social media project.
- CVSS 10
- Remote code execution exposure
New critical Fobybus Social-media-skeleton RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploit & PoC activity
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary cod...
A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0.
A vulnerability was found in PHP Jabbers Service Booking Script 1.0.
A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0.
A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0.
A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0.
A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0.
A vulnerability has been found in Academy LMS 6.0 and classified as problematic.
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a...
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauth...
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on...
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling a...
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devi...
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, af...
CloudExplorer Lite is an open source, lightweight cloud management platform.
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource.
Knowage is an open source analytics and business intelligence suite.
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to ove...
social-media-skeleton is an uncompleted social media project.
PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.
View critical disclosures
cvelogic
Threat Intelligence