Jan 17, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Citrix NetScaler ADC And NetScaler Gateway: 2 CVEs added to CISA KEV today.
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-6548 Citrix NetScaler ADC and NetScaler Gateway Code Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Citrix NetScaler ADC And NetScaler Gateway RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2021-4434 Warfareplugins Social Warfare RCE

  • CVSS 10
  • Internet-facing CMS deployments affected

New critical Warfareplugins Social Warfare RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-0643 Cires21 Live Encoder

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Citrix NetScaler ADC and NetScaler Gateway Code Injection

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow

Google Chromium V8 Out-of-Bounds Memory Access

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-4434 CVSS 10

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url'...

CVE-2023-44077 CVSS 9.8

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

CVE-2024-0642 CVSS 9.8

Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3.

CVE-2024-0643 CVSS 10

Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3.

CVE-2024-22416 CVSS 9.6

pyLoad is a free and open-source Download Manager written in pure Python.

View critical disclosures

cvelogic Threat Intelligence