Jul 28, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-41556 Fedoraproject Fedora Code Execution

  • CVSS 10
  • Remote code execution exposure

New critical Fedoraproject Fedora Code Execution (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-22683 Synology Media Server Buffer Overflow

  • CVSS 10

New critical Synology Media Server Buffer Overflow (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-30315 Honeywell Safety Manager Firmware RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Honeywell Safety Manager Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2016-4991 CVSS 9.8

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering.

CVE-2021-41556 CVSS 10

sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Ex...

CVE-2022-22683 CVSS 10

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8...

CVE-2022-2564 CVSS 9.8

Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.

CVE-2022-30315 CVSS 9.8

Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity.

CVE-2022-34555 CVSS 9.8

TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a c...

CVE-2022-34558 CVSS 9.8

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execut...

View critical disclosures

cvelogic Threat Intelligence