Mar 10, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Akaunting: public exploit or PoC linked (Command Injection)

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-4681 Wpwave Hide My Wp SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2024-22836 An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier.

  • Public exploit or PoC available
  • Exploit activity linked

Akaunting Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2024-2184 Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Pr...

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2024-27620 Exploit

An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.

CVE-2024-27612 Exploit

Numbas editor before 7.3 mishandles editing of themes and extensions.

CVE-2024-25830 Exploit

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction.

CVE-2024-25832 Exploit

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of...

CVE-2024-22836 Exploit

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier.

CVE-2022-4681 Exploit

The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-2184 CVSS 9.8

Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may a...

View critical disclosures

cvelogic Threat Intelligence