Aug 17, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-22455 Ibm Security Verify Governance privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Ibm Security Verify Governance privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-35121 Xxyopen Novel-plus SQL Injection

  • CVSS 9.8

New critical Xxyopen Novel-plus SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-35516 Dedecms RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Dedecms RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-1399 CVSS 9.1

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42...

CVE-2022-22455 CVSS 9.8

IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is highe...

CVE-2022-2336 CVSS 9.8

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin`...

CVE-2022-23747 CVSS 9.8

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being pass...

CVE-2022-35121 CVSS 9.8

Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.

CVE-2022-35122 CVSS 9.1

An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive i...

CVE-2022-35147 CVSS 9.8

DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.

CVE-2022-35516 CVSS 9.8

DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.

CVE-2022-36190 CVSS 9.8

GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get.

View critical disclosures

cvelogic Threat Intelligence