Oct 3, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Arm Mali GPU Kernel Driver added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-4211 Arm Mali GPU Kernel Driver Use-After-Free

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Arm Mali GPU Kernel Driver Use-After-Free is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2023-33272 An issue was discovered in DTS Monitoring 3.57.0.

  • CVSS 9.8

New critical Dts Monitoring Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-33273 An issue was discovered in DTS Monitoring 3.57.0.

  • CVSS 9.8

New critical Dts Monitoring Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-33272 CVSS 9.8

An issue was discovered in DTS Monitoring 3.57.0.

CVE-2023-33273 CVSS 9.8

An issue was discovered in DTS Monitoring 3.57.0.

CVE-2023-39645 CVSS 9.8

Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop.

CVE-2023-39646 CVSS 9.8

Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop.

CVE-2023-39647 CVSS 9.8

Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop.

CVE-2023-39648 CVSS 9.8

Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop.

CVE-2023-39649 CVSS 9.8

Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop.

CVE-2023-39651 CVSS 9.8

Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tv...

CVE-2023-44973 CVSS 9.8

An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary cod...

CVE-2023-44974 CVSS 9.8

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code...

View critical disclosures

cvelogic Threat Intelligence