Aug 1, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Wavlink Wn533a8 Firmware: public exploit or PoC linked (XSS)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2004-2466 Efs Software Easy Chat Server Buffer Overflow

  • Public exploit or PoC available
  • Exploit activity linked

Efs Software Easy Chat Server Buffer Overflow now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-34048 Wavlink Wn533a8 Firmware XSS

  • Public exploit or PoC available
  • Exploit activity linked

Wavlink Wn533a8 Firmware XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-2595 Kromit Titra privilege escalation

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical Kromit Titra privilege escalation (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-2551 Exploit

The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer e...

CVE-2022-2552 Exploit

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system s...

CVE-2022-36446 Exploit

software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

CVE-2022-34046 Exploit

An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://I...

CVE-2022-34047 Exploit

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http:/...

CVE-2022-34048 Exploit

Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page para...

CVE-2004-2466 Exploit

chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possi...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1950 CVSS 9.8

The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action...

CVE-2022-2317 CVSS 9.8

The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient...

CVE-2022-2595 CVSS 10

Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.

CVE-2022-26437 CVSS 9.8

In httpclient, there is a possible out of bounds write due to uninitialized data.

CVE-2022-27255 CVSS 9.8

In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow.

CVE-2022-31180 CVSS 9.8

Shescape is a simple shell escape package for JavaScript.

CVE-2022-31181 CVSS 9.8

PrestaShop is an Open Source e-commerce platform.

CVE-2022-31183 CVSS 9.1

fs2 is a compositional, streaming I/O library for Scala.

CVE-2022-31321 CVSS 9.1

The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumera...

CVE-2022-36301 CVSS 9.8

BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device pa...

View critical disclosures

cvelogic Threat Intelligence