Critical active threat
CVE-2023-45249 Acronis Cyber Infrastructure (ACI) Insecure Default Password
- Actively exploited (CISA KEV)
- Listed on CISA KEV
Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
Confirmed in-the-wild exploitation per CISA KEV — active threat momentum, not theoretical risk.
Critical exposure
New critical Admidio SQL Injection (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Oretnom23 Lost And Found Information System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
CISA KEV — confirmed in-the-wild exploitation.
Acronis Cyber Infrastructure (ACI) Insecure Default Password
ServiceNow Improper Input Validation
ServiceNow Incomplete List of Disallowed Inputs
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215.
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter...
Admidio is a free, open source user management system for websites of organizations and groups.
Admidio is a free, open source user management system for websites of organizations and groups.
The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthen...
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload medi...
The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated...
The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated...