Aug 11, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2020-36034 School Faculty Scheduling System Project School Faculty Scheduling System SQL Injection

  • CVSS 9.8

New critical School Faculty Scheduling System Project School Faculty Scheduling System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-36082 Bloofoxcms privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Bloofoxcms privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-28411 Ruoyi privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Ruoyi privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-27514 CVSS 9.1

Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to...

CVE-2020-27544 CVSS 9.8

An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remot...

CVE-2020-36034 CVSS 9.8

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code,...

CVE-2020-36082 CVSS 9.8

File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via cr...

CVE-2021-26505 CVSS 9.8

Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils....

CVE-2021-27523 CVSS 9.8

An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information...

CVE-2021-28411 CVSS 9.8

An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, all...

CVE-2023-3824 CVSS 9.4

In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory ent...

CVE-2023-40260 CVSS 9.1

EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username an...

CVE-2023-40267 CVSS 9.8

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from.

View critical disclosures

cvelogic Threat Intelligence