Nov 10, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-38119 UPSMON Pro login function has insufficient authentication.

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Upspowercom Upsmon Pro privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-39396 Parseplatform Parse-server RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Parseplatform Parse-server RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-44087 Ecisp Espcms RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Ecisp Espcms RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-38119 CVSS 9.8

UPSMON Pro login function has insufficient authentication.

CVE-2022-39036 CVSS 9.8

The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs.

CVE-2022-39395 CVSS 9.6

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang.

CVE-2022-39396 CVSS 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.

CVE-2022-43074 CVSS 9.8

AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php.

CVE-2022-44087 CVSS 9.8

ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.

CVE-2022-44088 CVSS 9.8

ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.

CVE-2022-44089 CVSS 9.8

ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.

CVE-2022-44727 CVSS 9.1

The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).

CVE-2022-45063 CVSS 9.8

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execu...

View critical disclosures

cvelogic Threat Intelligence