May 31, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-23692 Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-33999 The referrer URL used by MFA required additional sanitizing, rather than being used directly.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-36108 casgate is an Open Source Identity and Access Management system.

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-1275 CVSS 9.1

Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation...

CVE-2024-23692 CVSS 9.8

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine

CVE-2024-31030 CVSS 9.1

An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentially disclose info...

CVE-2024-33999 CVSS 9.8

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

CVE-2024-36108 CVSS 9.8

casgate is an Open Source Identity and Access Management system.

CVE-2024-36246 CVSS 9.8

Missing authorization vulnerability exists in Unifier and Unifier Cast.

CVE-2024-5176 CVSS 9.4

Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credent...

View critical disclosures

cvelogic Threat Intelligence