Nov 10, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-4804 Johnsoncontrols Quantum Hd Unity Acuair Firmware

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-39796 Wbce Cms SQL Injection

  • CVSS 9.8

New critical Wbce Cms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-47246 SysAid Server Path Traversal

  • CVSS 9.8
  • Remote code execution exposure

New critical SysAid Server Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-39796 CVSS 9.8

SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code v...

CVE-2023-46850 CVSS 9.8

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending...

CVE-2023-47128 CVSS 9.1

Piccolo is an object-relational mapping and query builder which supports asyncio.

CVE-2023-47800 CVSS 9.8

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allo...

CVE-2023-4804 CVSS 10

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

View critical disclosures

cvelogic Threat Intelligence