Aug 10, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • TP-Link Archer AX21: public exploit or PoC linked (Command Injection)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-1389 TP-Link Archer AX-21 Command Injection

  • Public exploit or PoC available
  • Exploit activity linked

TP-Link Archer AX21 Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-47636 Outsystems Service Studio

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2023-32560 Ivanti Avalanche RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Ivanti Avalanche RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-47636 Exploit

A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-32560 CVSS 9.8

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary...

CVE-2023-32562 CVSS 9.8

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacke...

CVE-2023-32563 CVSS 9.8

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

CVE-2023-32564 CVSS 9.8

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacke...

CVE-2023-32565 CVSS 9.1

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

CVE-2023-32567 CVSS 9.8

Ivanti Avalanche decodeToMap XML External Entity Processing.

CVE-2023-35085 CVSS 9.8

An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and defau...

CVE-2023-38034 CVSS 9.8

A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, co...

CVE-2023-39805 CVSS 9.8

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

CVE-2023-39806 CVSS 9.8

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.

View critical disclosures

cvelogic Threat Intelligence