Jan 12, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-49255 Hongdian H8951-4g-esp Firmware privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Hongdian H8951-4g-esp Firmware privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-49253 Root user password is hardcoded into the device and cannot be changed in the user interface.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2023-49262 Hongdian H8951-4g-esp Firmware

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption...

CVE-2023-31029 CVSS 9.3

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker...

CVE-2023-31030 CVSS 9.3

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by send...

CVE-2023-46943 CVSS 9.1

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8.

CVE-2023-49253 CVSS 9.8

Root user password is hardcoded into the device and cannot be changed in the user interface.

CVE-2023-49255 CVSS 9.8

The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the co...

CVE-2023-49262 CVSS 9.8

The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active u...

CVE-2023-51698 CVSS 9.6

Atril is a simple multi-page document viewer.

CVE-2024-21887 CVSS 9.1

Ivanti Connect Secure and Policy Secure Command Injection

View critical disclosures

cvelogic Threat Intelligence