Jun 28, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-31056 Glpi-project Glpi SQL Injection

  • CVSS 9.8

New critical Glpi-project Glpi SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-31061 Glpi-project Glpi SQL Injection

  • CVSS 9.8

New critical Glpi-project Glpi SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-31885 Marvalglobal Marval Msm Command Injection

  • CVSS 9.8

New critical Marvalglobal Marval Msm Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-19896 CVSS 9.8

File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.

CVE-2022-31056 CVSS 9.8

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

CVE-2022-31061 CVSS 9.8

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

CVE-2022-31229 CVSS 9.6

Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information.

CVE-2022-31885 CVSS 9.8

Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

CVE-2022-31887 CVSS 9.8

Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the orga...

CVE-2022-34132 CVSS 9.8

Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.

View critical disclosures

cvelogic Threat Intelligence