Nov 28, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Google Chromium GPU added to CISA KEV — confirmed in-the-wild exploitation.
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-4135 Google Chromium GPU Heap Buffer Overflow

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Google Chromium GPU Buffer Overflow is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-36193 Lahirudanushka School Management System SQL Injection

  • CVSS 9.8

New critical Lahirudanushka School Management System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-44283 AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

  • CVSS 9.8

New critical Avs4you Avs Audio Converter Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-3603 CVSS 9.8

The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not va...

CVE-2022-36193 CVSS 9.8

SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the applica...

CVE-2022-41912 CVSS 9.1

The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing mu...

CVE-2022-44283 CVSS 9.8

AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

CVE-2022-44399 CVSS 9.8

Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.

CVE-2022-44400 CVSS 9.8

Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.

CVE-2022-44401 CVSS 9.8

Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.

View critical disclosures

cvelogic Threat Intelligence