Jul 14, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-28373 Verizon Lvskihp Indoorunit Firmware RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Verizon Lvskihp Indoorunit Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-28375 Verizon Lvskihp Outdoorunit Firmware RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Verizon Lvskihp Outdoorunit Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-30113 Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.

  • CVSS 9.8

New critical Fahou100 Electronic Mall System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-25800 CVSS 9.1

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

CVE-2022-25801 CVSS 9.1

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

CVE-2022-28369 CVSS 9.8

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub...

CVE-2022-28373 CVSS 9.8

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition fu...

CVE-2022-28375 CVSS 9.8

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofil...

CVE-2022-30113 CVSS 9.8

Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.

CVE-2022-32409 CVSS 9.8

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows a...

CVE-2022-32417 CVSS 9.8

PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

View critical disclosures

cvelogic Threat Intelligence