Feb 8, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Dwbooster Cp Blocks: public exploit or PoC linked (XSS)
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2020-35749 Presstigers Simple Board Job Directory Traversal

  • Public exploit or PoC available
  • Exploit activity linked

Presstigers Simple Board Job Directory Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2021-24901 Securemoz Security Audit XSS

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Critical exposure

CVE-2022-24677 Hyphp Hybbs2 RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Hyphp Hybbs2 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-0448 Exploit

The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege use...

CVE-2021-24901 Exploit

The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege user...

CVE-2021-46398 Exploit

A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin priv...

CVE-2022-24263 Exploit

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php vi...

CVE-2020-35749 Exploit

Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier...

CVE-2019-18818 Exploit

strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-user...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-45327 CVSS 9.8

Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.

CVE-2022-0139 CVSS 9.8

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-0525 CVSS 9.1

Out-of-bounds Read in Homebrew mruby prior to 3.2.

CVE-2022-21241 CVSS 9.6

Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an ar...

CVE-2022-23340 CVSS 9.8

Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.

CVE-2022-24677 CVSS 9.8

Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

View critical disclosures

cvelogic Threat Intelligence