Jun 23, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-31361 Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability.

  • CVSS 9.8

New critical Docebo SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-31787 IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO

  • CVSS 9.8

New critical Ideaco Ideatms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-40954 Laiketui

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-40954 CVSS 9.8

Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

CVE-2022-22980 CVSS 9.8

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL exp...

CVE-2022-31361 CVSS 9.8

Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability.

CVE-2022-31787 CVSS 9.8

IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO

CVE-2022-32554 CVSS 9.8

Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity/...

CVE-2022-33127 CVSS 9.8

The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment.

CVE-2022-34181 CVSS 9.1

Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory if it doesn't ex...

View critical disclosures

cvelogic Threat Intelligence