Nov 5, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2024-51115 DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.

  • CVSS 9.8

New critical Dcnetworks Dcme-320 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-48176 Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-42509 Command injection vulnerability in the underlying CLI service could lead to unauthenticated remot...

  • CVSS 9.8
  • Remote code execution exposure

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-29120 CVSS 9.6

Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the W...

CVE-2023-29121 CVSS 9.6

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.

CVE-2024-42509 CVSS 9.8

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially cr...

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially cr...

CVE-2024-48176 CVSS 9.8

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control.

CVE-2024-48746 CVSS 9.8

An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language p...

CVE-2024-51115 CVSS 9.8

DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.

CVE-2024-51132 CVSS 9.8

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitra...

CVE-2024-51358 CVSS 9.8

An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new applicat...

View critical disclosures

cvelogic Threat Intelligence