Dec 15, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-44588 Unauth.

  • CVSS 9.9

New critical Blocksera Cryptocurrency Widgets Pack SQL Injection (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-42837 An issue existed in the parsing of URLs.

  • CVSS 9.8
  • Remote code execution exposure

New critical Apple Ipados RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-42842 The issue was addressed with improved memory handling.

  • CVSS 9.8
  • Remote code execution exposure

New critical Apple Ipados Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-4226 CVSS 9.8

RSFirewall tries to identify the original IP address by looking at different HTTP headers.

CVE-2022-40004 CVSS 9.6

Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit...

CVE-2022-42842 CVSS 9.8

The issue was addressed with improved memory handling.

CVE-2022-44236 CVSS 9.8

Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.

CVE-2022-45969 CVSS 9.8

Alist v3.4.0 is vulnerable to Directory Traversal,

CVE-2022-46393 CVSS 9.8

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.

CVE-2022-46631 CVSS 9.8

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the s...

CVE-2022-46634 CVSS 9.8

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the s...

View critical disclosures

cvelogic Threat Intelligence