Jun 6, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-31481 Carrier Ep4502 Firmware

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2022-1680 Gitlab

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2022-30927 Simple Task Scheduling System Project Simple Task Scheduling System SQL Injection

  • CVSS 9.8

New critical Simple Task Scheduling System Project Simple Task Scheduling System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1680 CVSS 9.9

An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions startin...

CVE-2022-30927 CVSS 9.8

A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application database.

CVE-2022-31479 CVSS 9.6

An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed durin...

CVE-2022-31481 CVSS 10

An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer.

CVE-2022-31483 CVSS 9.1

An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anyw...

CVE-2022-31768 CVSS 9.8

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection.

CVE-2022-32511 CVSS 9.8

jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

View critical disclosures

cvelogic Threat Intelligence