May 23, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Windows: 8 CVEs added to CISA KEV today.
  • Blog Project Blog: public exploit or PoC linked
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2018-5002 Adobe Flash Player Stack-based Buffer Overflow

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Adobe Flash Player RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2022-23626 m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog.

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2022-0781 Nirweb Support SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Nirweb Support SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Windows Kernel Privilege Escalation

Microsoft Update Notification Manager Privilege Escalation

Microsoft Windows AppX Deployment Extensions Privilege Escalation

View KEV additions

Exploit & PoC activity

CVE-2022-23626 Exploit

m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-32941 CVSS 9.4

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow,...

CVE-2022-0781 CVSS 9.8

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX...

CVE-2022-1014 CVSS 9.8

The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated...

CVE-2022-28932 CVSS 9.8

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

CVE-2022-29599 CVSS 9.8

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping,...

View critical disclosures

cvelogic Threat Intelligence