Feb 28, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Casbin Casdoor: public exploit or PoC linked (SQL Injection)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-24124 Casbin Casdoor SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked

Casbin Casdoor SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-43086 ARM astcenc 3.2.0 is vulnerable to Buffer Overflow.

  • CVSS 9.8

New critical Arm Adaptive Scalable Texture Compression Encoder Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-45414 Datarobot RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Datarobot RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-24124 Exploit

The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by ap...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-25010 CVSS 9.6

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admi...

CVE-2021-43086 CVSS 9.8

ARM astcenc 3.2.0 is vulnerable to Buffer Overflow.

CVE-2021-45414 CVSS 9.8

A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment o...

CVE-2022-0412 CVSS 9.8

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise an...

CVE-2022-0768 CVSS 9.1

Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

CVE-2022-24571 CVSS 9.8

Car Driving School Management System v1.0 is affected by SQL injection in the login page.

CVE-2022-24711 CVSS 9.4

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework.

CVE-2022-25411 CVSS 9.8

A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafte...

View critical disclosures

cvelogic Threat Intelligence