Jun 21, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-26147 The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

  • CVSS 9.8

New critical Quectel Rg502q-ea Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-29774 iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.

  • CVSS 9.8

New critical Ispyconnect Ispy Path Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-29775 iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-26147 CVSS 9.8

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

CVE-2022-29774 CVSS 9.8

iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.

CVE-2022-29775 CVSS 9.8

iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

CVE-2022-31374 CVSS 9.8

An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code vi...

CVE-2022-31800 CVSS 9.8

An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control...

CVE-2022-31801 CVSS 9.8

An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full con...

CVE-2022-33139 CVSS 9.8

A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC W...

View critical disclosures

cvelogic Threat Intelligence