Oct 31, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-42925 Formalms privilege escalation

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical Formalms privilege escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-41552 Hitachi Infrastructure Analytics Advisor SSRF

  • CVSS 9.8

New critical Hitachi Infrastructure Analytics Advisor SSRF (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-41772 Deltaww Infrasuite Device Master RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Deltaww Infrasuite Device Master RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-2572 CVSS 9.8

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/k...

The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality...

The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leve...

The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which coul...

CVE-2022-40293 CVSS 9.8

The application was vulnerable to a session fixation that could be used hijack accounts.

CVE-2022-40296 CVSS 9.8

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoint...

CVE-2022-41552 CVSS 9.8

Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics p...

CVE-2022-41772 CVSS 9.8

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traver...

CVE-2022-42925 CVSS 9.9

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to...

CVE-2022-44542 CVSS 9.8

lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution...

View critical disclosures

cvelogic Threat Intelligence