Critical active threat
CVE-2023-7028 GitLab Community and Enterprise Editions Improper Access Control
- Actively exploited (CISA KEV)
- Listed on CISA KEV
Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.
Critical exposure
New critical Libmodbus Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Fedoraproject Fedora Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
CISA KEV — confirmed in-the-wild exploitation.
GitLab Community and Enterprise Editions Improper Access Control
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.
An issue was discovered in Teledyne FLIR M300 2.00-19.
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22.
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0.
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execut...
There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sen...
Tencent Libpag v4.3 is vulnerable to Buffer Overflow.
There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code exe...
There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated...
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory.