Oct 25, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Apple IOS And IPadOS added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-42827 Apple iOS and iPadOS Out-of-Bounds Write

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Apple IOS And IPadOS Out-of-Bounds Write is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-35875 Goabode Iota All-in-one Security Kit Firmware DoS

  • CVSS 9.8

New critical Goabode Iota All-in-one Security Kit Firmware DoS (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-35876 Goabode Iota All-in-one Security Kit Firmware DoS

  • CVSS 9.8

New critical Goabode Iota All-in-one Security Kit Firmware DoS (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-3393 CVSS 9.8

The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CS...

CVE-2022-35875 CVSS 9.8

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.

CVE-2022-35876 CVSS 9.8

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.

CVE-2022-35877 CVSS 9.8

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc.

CVE-2022-36452 CVSS 9.8

New critical Mitel Micollab exposure disclosed.

CVE-2022-38580 CVSS 9.8

Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

CVE-2022-39312 CVSS 9.8

Dataease is an open source data visualization analysis tool.

CVE-2022-39322 CVSS 9.1

@keystone-6/core is a core package for Keystone 6, a content management system for Node.js.

CVE-2022-39345 CVSS 9.8

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack.

CVE-2022-41711 CVSS 9.8

Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server.

View critical disclosures

cvelogic Threat Intelligence