Jan 13, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Debian Linux: public exploit or PoC linked (SQL Injection)
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-21661 Debian Linux SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Critical exposure

CVE-2021-40722 Adobe Experience Manager XXE

  • CVSS 9.8

New critical Adobe Experience Manager XXE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-33046 Some Dahua products have access control vulnerability in the password reset process.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-21661 Exploit

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-30285 CVSS 9.3

Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Snapdrago...

CVE-2021-33046 CVSS 9.8

Some Dahua products have access control vulnerability in the password reset process.

CVE-2021-34993 CVSS 9.8

This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22.

CVE-2021-40722 CVSS 9.8

AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerab...

CVE-2021-45807 CVSS 9.8

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

CVE-2022-22989 CVSS 9.8

My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenti...

View critical disclosures

cvelogic Threat Intelligence