Aug 29, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-3262 Trispark Novusedu SQL injection

  • CVSS 9.8

New critical Trispark Novusedu SQL injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-34039 Vmware Aria Operations For Networks Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Vmware Aria Operations For Networks Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-40787 Bladex Springblade SQL Injection

  • CVSS 9.8

New critical Bladex Springblade SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-18912 CVSS 9.8

An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

CVE-2021-3262 CVSS 9.8

TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body para...

CVE-2023-23770 CVSS 9.4

Motorola MBTS Site Controller accepts hard-coded backdoor password.

CVE-2023-34039 CVSS 9.8

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation.

CVE-2023-40787 CVSS 9.8

In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to S...

CVE-2023-40889 CVSS 9.8

A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90.

CVE-2023-40890 CVSS 9.8

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90.

CVE-2023-41360 CVSS 9.1

An issue was discovered in FRRouting FRR through 9.0.

CVE-2023-41361 CVSS 9.8

An issue was discovered in FRRouting FRR 9.0.

View critical disclosures

cvelogic Threat Intelligence