May 20, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-29165 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2022-22972 Vmware Cloud Foundation Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Vmware Cloud Foundation Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-28531 Covid-19 Directory On Vaccination System Project Covid-19 Directory On Vaccination System SQL Injection

  • CVSS 9.8

New critical Covid-19 Directory On Vaccination System Project Covid-19 Directory On Vaccination System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1775 CVSS 9.8

Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-22972 CVSS 9.8

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local doma...

CVE-2022-28531 CVSS 9.8

Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Userna...

CVE-2022-28618 CVSS 9.8

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Ar...

CVE-2022-28660 CVSS 9.8

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is u...

CVE-2022-28995 CVSS 9.8

Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.

CVE-2022-29165 CVSS 10

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

CVE-2022-29186 CVSS 9.1

Rundeck is an open source automation service with a web console, command line tools and a WebAPI.

CVE-2022-30886 CVSS 9.8

School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/rep...

CVE-2022-30887 CVSS 9.8

Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editP...

View critical disclosures

cvelogic Threat Intelligence