Apr 15, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Openclinic Ga Project Openclinic Ga: public exploit or PoC linked (Info Disclosure)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2023-40278 An issue was discovered in OpenClinic GA 5.247.01.

  • Public exploit or PoC available
  • Exploit activity linked

Openclinic Ga Project Openclinic Ga Info Disclosure now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2023-40279 An issue was discovered in OpenClinic GA 5.247.01.

  • Public exploit or PoC available
  • Exploit activity linked

Openclinic Ga Project Openclinic Ga Path Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2024-2912 An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code e...

  • CVSS 10
  • Remote code execution exposure

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2023-40278 Exploit

An issue was discovered in OpenClinic GA 5.247.01.

CVE-2023-40279 Exploit

An issue was discovered in OpenClinic GA 5.247.01.

CVE-2024-22513 Exploit

djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure.

CVE-2024-23897 Exploit

Jenkins Command Line Interface (CLI) Path Traversal

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-0404 CVSS 9.1

A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unautho...

CVE-2024-1601 CVSS 9.8

An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacke...

CVE-2024-1739 CVSS 9.1

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process.

CVE-2024-2083 CVSS 9.9

A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint.

CVE-2024-28556 CVSS 9.8

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalat...

CVE-2024-28557 CVSS 9.8

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalat...

CVE-2024-2912 CVSS 10

An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially cr...

CVE-2024-31650 CVSS 9.6

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML...

CVE-2024-3271 CVSS 9.8

A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function.

CVE-2024-3573 CVSS 9.3

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read a...

View critical disclosures

cvelogic Threat Intelligence