Jan 10, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Win32k: 2 CVEs added to CISA KEV today.
  • Coreftp Core Ftp: public exploit or PoC linked (Directory Traversal)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2013-3900 Microsoft WinVerifyTrust function Remote Code Execution

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Microsoft WinVerifyTrust Function RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2009-0182 Vuplayer Buffer Overflow

  • Public exploit or PoC available
  • Exploit activity linked

Vuplayer Buffer Overflow now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-24949 Posimyth The Plus Addons For Elementor SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Posimyth The Plus Addons For Elementor SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

Palo Alto Networks PAN-OS Remote Code Execution

Exim Mail Transfer Agent (MTA) Improper Input Validation

Fortinet FortiOS and FortiProxy Improper Authorization

Fortinet FortiOS and FortiProxy Out-of-bounds Write

Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

View KEV additions

Exploit & PoC activity

CVE-2022-22836 Exploit

CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.

CVE-2021-44916 Exploit

Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability.

CVE-2009-0182 Exploit

Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-24949 CVSS 9.8

The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the opti...

CVE-2021-25032 CVSS 9.8

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have au...

CVE-2021-43297 CVSS 9.8

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution.

CVE-2022-22114 CVSS 9.6

In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS).

In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag.

CVE-2022-22822 CVSS 9.8

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVE-2022-22823 CVSS 9.8

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVE-2022-22824 CVSS 9.8

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVE-2022-22845 CVSS 9.8

QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different c...

CVE-2022-22847 CVSS 9.8

Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in a configuration...

View critical disclosures

cvelogic Threat Intelligence