Dec 26, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 3 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2019-11851 Sierrawireless Aleos Buffer Overflow

  • CVSS 9.8

New critical Sierrawireless Aleos Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-11101 Sierrawireless Airlink Mobility Manager privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Sierrawireless Airlink Mobility Manager privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-24600 Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.

  • CVSS 9.8

New critical Capexweb Project Capexweb SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2019-11851 CVSS 9.8

The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allow...

CVE-2020-11101 CVSS 9.8

Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login se...

CVE-2020-24600 CVSS 9.8

Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.

CVE-2022-24118 CVSS 9.1

Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration.

CVE-2022-24119 CVSS 9.8

Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration sh...

CVE-2022-26969 CVSS 9.8

In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.

CVE-2022-4047 CVSS 9.8

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJA...

CVE-2022-4117 CVSS 9.8

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available...

CVE-2022-4120 CVSS 9.8

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the uns...

CVE-2022-46764 CVSS 9.8

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to exe...

View critical disclosures

cvelogic Threat Intelligence