Dec 1, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-30528 Isic.lk Project Isic.lk SQL Injection

  • CVSS 9.8

New critical Isic.lk Project Isic.lk SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-37016 Broadcom Symantec Endpoint Protection Privilege Escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Broadcom Symantec Endpoint Protection Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-4221 Asus Nas-m25 Firmware Command Injection

  • CVSS 9.8

New critical Asus Nas-m25 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-30528 CVSS 9.8

SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arb...

CVE-2022-3270 CVSS 9.8

In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a com...

CVE-2022-36431 CVSS 9.8

An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrar...

CVE-2022-37016 CVSS 9.8

Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby...

CVE-2022-4221 CVSS 9.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauth...

CVE-2022-43333 CVSS 9.8

Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action...

CVE-2022-44262 CVSS 9.8

ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

View critical disclosures

cvelogic Threat Intelligence