Jul 13, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-20222 Google Android RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Google Android RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-20229 Google Android RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Google Android RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-35857 Kvf-admin Project Kvf-admin Deserialization

  • CVSS 9.8

New critical Kvf-admin Project Kvf-admin Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-20216 CVSS 9.8

android exported is used to set third-party app access permissions, and the default value of intent-filter is true.

CVE-2022-20222 CVSS 9.8

In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check.

CVE-2022-20229 CVSS 9.8

In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check.

CVE-2022-20238 CVSS 9.8

'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can...

CVE-2022-28888 CVSS 9.8

Spryker Commerce OS 1.4.2 allows Remote Command Execution.

CVE-2022-32073 CVSS 9.8

WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.

CVE-2022-35857 CVSS 9.8

kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled.

View critical disclosures

cvelogic Threat Intelligence