Mar 6, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Apple Multiple Products: 2 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-23225 Apple Multiple Products Memory Corruption

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Apple Multiple Products Memory Corruption is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2023-49989 Pratham-jaiswal Hotel Booking Management System SQL Injection

  • CVSS 9.8

New critical Pratham-jaiswal Hotel Booking Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-27304 pgx is a PostgreSQL driver and toolkit for Go.

  • CVSS 9.8

New critical Jackc Pgproto3 SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-49989 CVSS 9.8

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

CVE-2023-50716 CVSS 9.6

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group.

CVE-2023-51786 CVSS 9.1

An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain s...

CVE-2024-2005 CVSS 9

In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation.

CVE-2024-22857 CVSS 9.8

Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may ha...

CVE-2024-24767 CVSS 9.1

CasaOS-UserService provides user management functionalities to CasaOS.

CVE-2024-26580 CVSS 9.1

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attacke...

CVE-2024-27304 CVSS 9.8

pgx is a PostgreSQL driver and toolkit for Go.

CVE-2024-27307 CVSS 9.8

JSONata is a JSON query and transformation language.

View critical disclosures

cvelogic Threat Intelligence