Jun 13, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-40036 The bone voice ID TA has a memory overwrite vulnerability.

  • CVSS 9.8
  • Remote code execution exposure

New critical Huawei Harmonyos Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-41661 Church Management System Project Church Management System SQL injection

  • CVSS 9.8

New critical Church Management System Project Church Management System SQL injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-41662 South Gate Inn Online Reservation System Project South Gate Inn Online Reservation System RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical South Gate Inn Online Reservation System Project South Gate Inn Online Reservation System RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-40036 CVSS 9.8

The bone voice ID TA has a memory overwrite vulnerability.

CVE-2021-40604 CVSS 9.1

A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbit...

CVE-2021-41661 CVSS 9.8

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar im...

CVE-2021-41662 CVSS 9.8

The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file u...

CVE-2022-29797 CVSS 9.8

There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46.

CVE-2022-31053 CVSS 9.8

Biscuit is an authentication and authorization token for microservices architectures.

CVE-2022-31446 CVSS 9.8

Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac paramet...

CVE-2022-31760 CVSS 9.1

Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services.

CVE-2022-33174 CVSS 9.8

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web inte...

CVE-2022-33175 CVSS 9.8

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.t...

View critical disclosures

cvelogic Threat Intelligence