Apr 1, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-51570 Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability.

  • CVSS 9.8
  • Remote code execution exposure

New critical Voltronicpower Viewpower RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-51572 Voltronicpower Viewpower RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Voltronicpower Viewpower RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2023-51573 Voltronicpower Viewpower Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Voltronicpower Viewpower Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-51570 CVSS 9.8

Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability.

CVE-2023-51572 CVSS 9.8

Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability.

CVE-2023-51573 CVSS 9.8

Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability.

CVE-2024-1863 CVSS 9.8

Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability.

CVE-2024-21473 CVSS 9.8

Memory corruption while redirecting log file to any file location with any file name.

CVE-2024-29433 CVSS 9.8

A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying...

CVE-2024-30858 CVSS 9.8

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

CVE-2024-30865 CVSS 9.8

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

CVE-2024-30867 CVSS 9.8

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

CVE-2024-30868 CVSS 9.8

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

View critical disclosures

cvelogic Threat Intelligence