Home
» Risk & Exploitation
» Daily threat intelligence
» Aug 2, 2022
Aug 2, 2022 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Troglobit Uftpd: public exploit or PoC linked (RCE)
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
Public exploit or PoC available
Exploit activity linked
Remote code execution exposure
Troglobit Uftpd RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2022-29807
Quest Kace Systems Management Appliance RCE
CVSS 9.8
Remote code execution exposure
New critical Quest Kace Systems Management Appliance RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2022-35223
Easyuse Mailhunter Ultimate Deserialization
New critical Easyuse Mailhunter Ultimate Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploit & PoC activity
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10...
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
This affects all versions of package monorepo-build.
This affects all versions of package gitblame.
This affects all versions of package heroku-env.
This affects the package image-tiler before 2.0.2.
This affects all versions of package npos-tesseract.
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code exe...
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication.
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.
EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability.
NextAuth.js is a complete open source authentication solution for Next.js applications.
View critical disclosures
cvelogic
Threat Intelligence