Aug 31, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-36130 Hashicorp Boundary Privilege Escalation

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Hashicorp Boundary Privilege Escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-30318 Honeywell ControlEdge through R151.1 uses Hard-coded Credentials.

  • CVSS 9.8
  • Remote code execution exposure

New critical Honeywell Controledge Plc Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-36566 Yogeshojha Rengine Command Injection

  • CVSS 9.8

New critical Yogeshojha Rengine Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-30317 CVSS 9.1

Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function.

CVE-2022-30318 CVSS 9.8

Honeywell ControlEdge through R151.1 uses Hard-coded Credentials.

CVE-2022-36130 CVSS 9.9

HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct s...

CVE-2022-36201 CVSS 9.8

Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.

CVE-2022-36202 CVSS 9.8

Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php.

CVE-2022-36566 CVSS 9.8

Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

CVE-2022-36672 CVSS 9.8

Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file.

CVE-2022-37125 CVSS 9.8

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

CVE-2022-37128 CVSS 9.8

In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

CVE-2022-37130 CVSS 9.8

In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the c...

View critical disclosures

cvelogic Threat Intelligence