Jan 8, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Adobe ColdFusion: 2 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2016-20017 D-Link DSL-2750B Devices Command Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

D-Link DSL-2750B Devices Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2023-52218 Antonbond Woocommerce Tranzila Payment Gateway Deserialization

  • CVSS 10

New critical Antonbond Woocommerce Tranzila Payment Gateway Deserialization (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-52225 Taggbox Deserialization

  • CVSS 10

New critical Taggbox Deserialization (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Adobe ColdFusion Deserialization of Untrusted Data

Adobe ColdFusion Deserialization of Untrusted Data

Apache Superset Insecure Default Initialization of Resource

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-25095 CVSS 9.8

The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress confi...

Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysCon...

CVE-2023-52200 CVSS 9.6

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Co...

CVE-2023-52202 CVSS 9.1

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue aff...

CVE-2023-52205 CVSS 9.1

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5...

CVE-2023-52207 CVSS 9.1

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Pla...

CVE-2023-52215 CVSS 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Manage...

CVE-2023-52218 CVSS 10

Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzil...

CVE-2023-52219 CVSS 9.9

Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a throu...

CVE-2023-52225 CVSS 10

Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This iss...

View critical disclosures

cvelogic Threat Intelligence