Dec 7, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-46742 Paddlepaddle RCE

  • CVSS 10
  • Remote code execution exposure

New critical Paddlepaddle RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-42458 Shift-tech Bingo\!cms Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Shift-tech Bingo\!cms Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-44351 Skycaiji Deserialization

  • CVSS 9.8

New critical Skycaiji Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-42458 CVSS 9.8

Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenti...

CVE-2022-44351 CVSS 9.8

Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.

CVE-2022-44371 CVSS 9.8

hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).

CVE-2022-45010 CVSS 9.8

Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/e...

CVE-2022-45025 CVSS 9.8

Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF...

CVE-2022-45026 CVSS 9.8

An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GF...

CVE-2022-45550 CVSS 9.8

AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).

CVE-2022-46742 CVSS 10

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.

View critical disclosures

cvelogic Threat Intelligence