Aug 4, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Campcodes Complete Online Matrimonial Website System Script: public exploit or PoC linked (cross-site scripting)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-2796 Myeventon Eventon privilege escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2023-33383 Shelly Pro 4pm Firmware memory safety

  • Public exploit or PoC available
  • Exploit activity linked

Shelly Pro 4pm Firmware memory safety now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2023-39344 social-media-skeleton is an uncompleted social media project.

  • CVSS 10
  • Remote code execution exposure

New critical Fobybus Social-media-skeleton RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-39115 Exploit

install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

CVE-2023-36306 Exploit

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary cod...

CVE-2023-4112 Exploit

A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0.

CVE-2023-4113 Exploit

A vulnerability was found in PHP Jabbers Service Booking Script 1.0.

CVE-2023-4114 Exploit

A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0.

CVE-2023-4115 Exploit

A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0.

CVE-2023-4116 Exploit

A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0.

CVE-2023-4117 Exploit

A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0.

CVE-2023-4119 Exploit

A vulnerability has been found in Academy LMS 6.0 and classified as problematic.

CVE-2023-33383 Exploit

Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a...

CVE-2023-2796 Exploit

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauth...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-33367 CVSS 9.8

A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on...

CVE-2023-33378 CVSS 9.8

Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling a...

CVE-2023-33379 CVSS 9.8

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devi...

CVE-2023-36095 CVSS 9.8

An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, af...

CVE-2023-38692 CVSS 9.8

CloudExplorer Lite is an open source, lightweight cloud management platform.

CVE-2023-38699 CVSS 9.1

MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource.

CVE-2023-38702 CVSS 9.9

Knowage is an open source analytics and business intelligence suite.

CVE-2023-39107 CVSS 9.1

An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to ove...

CVE-2023-39344 CVSS 10

social-media-skeleton is an uncompleted social media project.

CVE-2023-39551 CVSS 9.8

PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.

View critical disclosures

cvelogic Threat Intelligence