Mar 15, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-28354 Trendnet Tew-827dru Firmware Command Injection

  • CVSS 10

New critical Trendnet Tew-827dru Firmware Command Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-25227 Abocms Abo.cms DoS

  • CVSS 9.8

New critical Abocms Abo.cms DoS (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-28255 Open-metadata Openmetadata

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-7006 CVSS 9.1

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks...

CVE-2023-7017 CVSS 9.8

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low...

CVE-2024-25227 CVSS 9.8

SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), e...

CVE-2024-28253 CVSS 9.4

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineag...

CVE-2024-28255 CVSS 9.8

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineag...

CVE-2024-28354 CVSS 10

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01.

CVE-2024-28752 CVSS 9.3

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SS...

View critical disclosures

cvelogic Threat Intelligence