Aug 10, 2023 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- TP-Link Archer AX21: public exploit or PoC linked (Command Injection)
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2023-1389
TP-Link Archer AX-21 Command Injection
- Public exploit or PoC available
- Exploit activity linked
TP-Link Archer AX21 Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Active exploit activity
- Public exploit or PoC available
- Exploit activity linked
Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.
Critical exposure
- CVSS 9.8
- Remote code execution exposure
New critical Ivanti Avalanche RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploit & PoC activity
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739.
TP-Link Archer AX-21 Command Injection
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary...
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacke...
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacke...
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
Ivanti Avalanche decodeToMap XML External Entity Processing.
An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and defau...
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, co...
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
View critical disclosures
cvelogic
Threat Intelligence