Dec 1, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-48842 Dlink Go-rt-ac750 Firmware Command Injection

  • CVSS 9.8

New critical Dlink Go-rt-ac750 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-48886 Luxiaoxun Nettyrpc Deserialization

  • CVSS 9.8

New critical Luxiaoxun Nettyrpc Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-48887 Fengjiachun Jupiter Deserialization

  • CVSS 9.8

New critical Fengjiachun Jupiter Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-44382 CVSS 9.1

October is a Content Management System (CMS) and web platform to assist with development workflow.

CVE-2023-48801 CVSS 9.8

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them...

CVE-2023-48842 CVSS 9.8

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.

CVE-2023-48886 CVSS 9.8

A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.

CVE-2023-48887 CVSS 9.8

A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.

CVE-2023-49371 CVSS 9.8

RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.

CVE-2023-5634 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ArslanSoft Education Portal allows...

CVE-2023-5636 CVSS 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection.

View critical disclosures

cvelogic Threat Intelligence