Jun 15, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2017-20049 A vulnerability, was found in legacy Axis devices such as P3225 and M3005.

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Axis M3005 Firmware privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-20825 New critical Cisco Rv110w Firmware DoS disclosed.

  • CVSS 9.8
  • Network edge / SD-WAN deployments affected

New critical Cisco Rv110w Firmware DoS (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-30136 Windows Network File System Remote Code Execution Vulnerability

  • CVSS 9.8
  • Remote code execution exposure

New critical Microsoft Windows Server 2012 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2017-20049 CVSS 9.8

A vulnerability, was found in legacy Axis devices such as P3225 and M3005.

CVE-2021-40940 CVSS 9.8

Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

CVE-2021-41403 CVSS 9.8

flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.

CVE-2021-41418 CVSS 9.8

AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.

CVE-2022-20798 CVSS 9.8

New critical Cisco Email Security Appliance exposure disclosed.

CVE-2022-20825 CVSS 9.8

New critical Cisco Rv110w Firmware DoS disclosed.

CVE-2022-30136 CVSS 9.8

Windows Network File System Remote Code Execution Vulnerability

CVE-2022-32101 CVSS 9.8

kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployme...

CVE-2022-32301 CVSS 9.8

YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.clas...

View critical disclosures

cvelogic Threat Intelligence