Aug 10, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-35535 Wavlink Wn530h4 Firmware Command Injection

  • CVSS 9.8

New critical Wavlink Wn530h4 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-35536 Wavlink Wn530h4 Firmware Command Injection

  • CVSS 9.8

New critical Wavlink Wn530h4 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-35537 Wavlink Wn530h4 Firmware Command Injection

  • CVSS 9.8

New critical Wavlink Wn530h4 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-35535 CVSS 9.8

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection...

CVE-2022-35536 CVSS 9.8

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to com...

CVE-2022-35537 CVSS 9.8

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to comm...

CVE-2022-35538 CVSS 9.8

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_delete_li...

CVE-2022-36270 CVSS 9.8

Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.

CVE-2022-36750 CVSS 9.8

Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.

CVE-2022-37002 CVSS 9.8

The SystemUI module has a privilege escalation vulnerability.

CVE-2022-37003 CVSS 9.8

The AOD module has a vulnerability in permission assignment.

CVE-2022-38129 CVSS 9.8

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Senso...

CVE-2022-38130 CVSS 9.8

The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS.

View critical disclosures

cvelogic Threat Intelligence