Mar 7, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Adobe ColdFusion: 4 CVEs added to CISA KEV today.
  • Part-db Project Part-db: public exploit or PoC linked (Command Injection)
  • WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2009-3960 Adobe BlazeDS Information Disclosure

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Adobe BlazeDS Info Disclosure is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2022-0848 OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

  • Public exploit or PoC available
  • Exploit activity linked

Part-db Project Part-db Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-0767 Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

  • CVSS 9.9

New critical Janeczku Calibre-web SSRF (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF)

Atlassian Jira Server and Data Center Server-Side Template Injection

NETGEAR Multiple Routers Remote Code Execution

View KEV additions

Exploit & PoC activity

CVE-2022-0848 Exploit

OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-0349 CVSS 9.8

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, lead...

CVE-2022-0434 CVSS 9.8

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement...

CVE-2022-0441 CVSS 9.8

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthe...

CVE-2022-0766 CVSS 9.8

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVE-2022-0767 CVSS 9.9

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

View critical disclosures

cvelogic Threat Intelligence