Critical active threat
CVE-2018-14667 Red Hat JBoss RichFaces Framework Expression Language Injection
- Actively exploited (CISA KEV)
- Listed on CISA KEV
Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.
Critical exposure
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
New critical Oretnom23 Packers And Movers Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
CISA KEV — confirmed in-the-wild exploitation.
Red Hat JBoss RichFaces Framework Expression Language Injection
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page,...
TorchServe is a tool for serving and scaling PyTorch models in production.
The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the d...
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the dat...
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to th...
Hospital management system version 378c157 allows to bypass authentication.
Hospital management system version 378c157 allows to bypass authentication.
Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page,...