Dec 15, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-50721 XWiki Platform is a generic wiki platform.

  • CVSS 9.9
  • Remote code execution exposure

New critical Xwiki RCE (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-50723 XWiki Platform is a generic wiki platform.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2020-17485 A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions.

  • CVSS 9.8
  • Remote code execution exposure

New critical Uffizio Gps Tracker RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-17485 CVSS 9.8

A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions.

CVE-2021-42796 CVSS 9.8

An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthentic...

CVE-2023-4020 CVSS 9

An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone i...

CVE-2023-50089 CVSS 9.8

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70.

CVE-2023-50469 CVSS 9.8

Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter...

CVE-2023-50917 CVSS 9.8

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters.

CVE-2023-50918 CVSS 9.8

app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

View critical disclosures

cvelogic Threat Intelligence