Nov 5, 2024 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- 10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2024-51115
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
New critical Dcnetworks Dcme-320 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2024-48176
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control.
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2024-42509
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remot...
- CVSS 9.8
- Remote code execution exposure
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the W...
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially cr...
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially cr...
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control.
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language p...
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitra...
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new applicat...
View critical disclosures
cvelogic
Threat Intelligence