Nostromo Nhttpd RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVE-2024-50766Oretnom23 Survey Application System SQL Injection
CVSS 9.8
New critical Oretnom23 Survey Application System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2019-20461An issue was discovered on Alecto IVM-100 2019-11-12 devices.
CVSS 9.8
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.