Jun 14, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Windows added to CISA KEV — confirmed in-the-wild exploitation.
  • Marvalglobal Marval Msm: public exploit or PoC linked (Command Injection)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-30190 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Microsoft Windows RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2021-37589 Virtua Cobranca before 12R allows SQL Injection on the login page.

  • Public exploit or PoC available
  • Exploit activity linked

Virtuasoftware Cobranca SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-42675 Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory.

  • CVSS 9.8
  • Remote code execution exposure

New critical Kreado Kreasfero RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution

View KEV additions

Exploit & PoC activity

CVE-2022-31885 Exploit

Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

CVE-2022-31886 Exploit

Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF).

CVE-2022-29299 Exploit

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.

CVE-2022-29301 Exploit

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.

CVE-2022-30075 Exploit

In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution d...

CVE-2022-31325 Exploit

There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.

CVE-2021-37589 Exploit

Virtua Cobranca before 12R allows SQL Injection on the login page.

CVE-2022-29296 Exploit

A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute ar...

CVE-2022-23642 Exploit

Sourcegraph is a code search and navigation engine.

CVE-2020-5844 Exploit

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload maliciou...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-42675 CVSS 9.8

Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory.

CVE-2022-27668 CVSS 9.8

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to exec...

CVE-2022-30230 CVSS 9.3

A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).

CVE-2022-31273 CVSS 9.8

An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted...

CVE-2022-31311 CVSS 9.8

An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2022-32328 CVSS 9.1

Fast Food Ordering System v1.0 is vulnerable to Delete any file.

CVE-2022-32336 CVSS 9.8

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.

CVE-2022-32337 CVSS 9.8

Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=.

CVE-2022-32352 CVSS 9.8

Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission.

CVE-2022-32559 CVSS 9.1

An issue was discovered in Couchbase Server before 7.0.4.

View critical disclosures

cvelogic Threat Intelligence