NVD disclosure day

Published threat advisories for July 12, 2023

CVE advisoryKnown Exploit

CVE-2023-29300

Adobe ColdFusion Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe ColdFusion is affected by a deserialization vulnerability enabling arbitrary code execution without user interaction. This poses a significant risk to affected organizations, potentially leading to unauthorized system control and data compromise. Attackers can exploit this flaw by sending malicious data to expose

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-29298

Adobe ColdFusion Access Control Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper access control vulnerability in Adobe ColdFusion allows attackers to bypass security features and access administration endpoints. This bypass can lead to unauthorized access and potential data compromise. Organizations should identify affected systems and apply vendor-provided mitigations to reduce busines

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-33668

DigiExam Module Integrity Flaw Allows PII Access and Account Takeover.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in DigiExam, affecting versions up to 14.0.2, allows attackers to bypass integrity checks on native modules. This could lead to unauthorized access to PII and account takeovers on shared computers. Technical readers and security-aware leaders should care because this issue impacts user data privacy and