Nov 7, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Atlassian Confluence Data Center And Server added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-22518 Atlassian Confluence Data Center and Server Improper Authorization

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Potential privilege escalation to admin/root

Atlassian Confluence Data Center And Server privilege escalation is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2023-46243 Xwiki

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-46677 Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

  • CVSS 9.8

New critical Projectworlds Online Job Portal SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Atlassian Confluence Data Center and Server Improper Authorization

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-46243 CVSS 9.9

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.

CVE-2023-46253 CVSS 9.1

Squidex is an open source headless CMS and content management hub.

CVE-2023-46677 CVSS 9.8

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-46679 CVSS 9.8

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-46785 CVSS 9.8

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-46787 CVSS 9.8

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-46788 CVSS 9.8

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-46789 CVSS 9.8

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-46793 CVSS 9.8

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2023-46800 CVSS 9.8

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

View critical disclosures

cvelogic Threat Intelligence