Mar 13, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-6825 Mndpsingh287 File Manager Directory Traversal

  • CVSS 9.9
  • Internet-facing CMS deployments affected

New critical Mndpsingh287 File Manager Directory Traversal (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-27102 Wings is the server control plane for Pterodactyl Panel.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-0799 Arcserve Udp Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Arcserve Udp Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-41505 CVSS 9.8

An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers t...

CVE-2023-6825 CVSS 9.9

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including versio...

CVE-2024-0799 CVSS 9.8

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcse...

CVE-2024-1071 CVSS 9.8

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress i...

CVE-2024-2172 CVSS 9.8

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalat...

CVE-2024-25250 CVSS 9.8

SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

CVE-2024-27102 CVSS 9.9

Wings is the server control plane for Pterodactyl Panel.

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

CVE-2024-28194 CVSS 9.1

your_spotify is an open source, self hosted Spotify tracking dashboard.

CVE-2024-28388 CVSS 9.8

SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate...

View critical disclosures

cvelogic Threat Intelligence