Apr 3, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-28368 Dompdf Project Dompdf RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Dompdf Project Dompdf RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-28381 Allmediaserver Buffer Overflow

  • CVSS 9.8

New critical Allmediaserver Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-30064 Belden Eagle 20 Tofino 943 987-501-tx\/tx Firmware

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-30064 CVSS 9.8

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Applianc...

CVE-2022-26530 CVSS 9.1

swaylock before 1.6 allows attackers to trigger a crash and achieve unlocked access to a Wayland compositor.

CVE-2022-28368 CVSS 9.8

Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (w...

CVE-2022-28381 CVSS 9.8

Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long...

View critical disclosures

cvelogic Threat Intelligence