Mar 4, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-32008 This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2021-46384 https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.

  • CVSS 9.8
  • Remote code execution exposure

New critical Mingsoft Mcms RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-46393 Tenda Ax3 Firmware Buffer Overflow

  • CVSS 9.8

New critical Tenda Ax3 Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-32008 CVSS 9.9

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

CVE-2021-46384 CVSS 9.8

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.

CVE-2021-46393 CVSS 9.8

There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN.

CVE-2021-46394 CVSS 9.8

There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN.

CVE-2022-0839 CVSS 9.8

Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

CVE-2022-0848 CVSS 9.8

OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

CVE-2022-25069 CVSS 9.6

Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote...

CVE-2022-25312 CVSS 9.1

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any...

CVE-2022-26201 CVSS 9.8

Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.

CVE-2022-26318 CVSS 9.8

WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

View critical disclosures

cvelogic Threat Intelligence