Jul 5, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-31856 Newsletter Module Project Newsletter Module SQL Injection

  • CVSS 9.8

New critical Newsletter Module Project Newsletter Module SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-32311 Ingredient Stock Management System Project Ingredient Stock Management System SQL Injection

  • CVSS 9.8

New critical Ingredient Stock Management System Project Ingredient Stock Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-34972 So Filter Shop By Project So Filter Shop By SQL Injection

  • CVSS 9.8

New critical So Filter Shop By Project So Filter Shop By SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-2321 CVSS 9.8

Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0.

CVE-2022-31836 CVSS 9.8

The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.

CVE-2022-31856 CVSS 9.8

Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.

CVE-2022-32310 CVSS 9.8

An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request...

CVE-2022-32311 CVSS 9.8

Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stock...

CVE-2022-32413 CVSS 9.8

An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.

CVE-2022-34972 CVSS 9.8

So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_val...

View critical disclosures

cvelogic Threat Intelligence