Nov 23, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-3377 Veribase SQL Injection

  • CVSS 9.8

New critical Veribase SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-3631 Medart Notification Panel Project Medart Notification Panel SQL Injection

  • CVSS 9.8

New critical Medart Notification Panel Project Medart Notification Panel SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-49208 Glewlwyd Sso Server Project Glewlwyd Sso Server Buffer Overflow

  • CVSS 9.8

New critical Glewlwyd Sso Server Project Glewlwyd Sso Server Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-28812 CVSS 9.1

There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability by sending crafted...

CVE-2023-3377 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veribilim Software Computer Veribas...

CVE-2023-3631 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Medart Health Services Medart Notif...

CVE-2023-41807 CVSS 9.1

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation.

CVE-2023-49208 CVSS 9.8

scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn regi...

CVE-2023-49210 CVSS 9.8

The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, an...

CVE-2023-49214 CVSS 9.8

Usedesk before 1.7.57 allows chat template injection.

View critical disclosures

cvelogic Threat Intelligence