Apr 29, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-33350 Taogogo Taocms Directory Traversal

  • CVSS 9.8

New critical Taogogo Taocms Directory Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-31820 An issue in Ecommerce-CodeIgniter-Bootstrap commit v.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-31822 An issue in Ecommerce-CodeIgniter-Bootstrap commit v.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-50434 CVSS 9.8

emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-base...

CVE-2024-31820 CVSS 9.8

An issue in Ecommerce-CodeIgniter-Bootstrap commit v.

CVE-2024-31822 CVSS 9.8

An issue in Ecommerce-CodeIgniter-Bootstrap commit v.

CVE-2024-33266 CVSS 9.8

SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via...

CVE-2024-33268 CVSS 9.8

SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::...

CVE-2024-33269 CVSS 9.8

SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::...

CVE-2024-33276 CVSS 9.8

SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL command...

CVE-2024-33350 CVSS 9.8

Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information v...

CVE-2024-33435 CVSS 9.8

Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co.

CVE-2024-34048 CVSS 9.8

O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.

View critical disclosures

cvelogic Threat Intelligence