Dec 19, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-47267 Thegreenbow Vpn Client privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Thegreenbow Vpn Client privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-45887 Nintendo Ds Wireless Communication

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-49004 Dlink Dir-850l Firmware

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-27172 CVSS 9.1

Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens.

CVE-2023-45887 CVSS 9.8

DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing...

CVE-2023-46266 CVSS 9.1

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

CVE-2023-47267 CVSS 9.8

An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise...

CVE-2023-48738 CVSS 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functiona...

CVE-2023-49004 CVSS 9.8

An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.

CVE-2023-49750 CVSS 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate &...

CVE-2023-50707 CVSS 9.6

Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the de...

CVE-2023-6928 CVSS 9.8

EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password a...

CVE-2023-6930 CVSS 9.4

EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability.

View critical disclosures

cvelogic Threat Intelligence