Jan 5, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-44877 CWP Control Web Panel OS Command Injection

  • CVSS 9.8

New critical CWP Control Web Panel Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-45995 There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn.

  • CVSS 9.8

New critical Tenda Ax12 Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-47523 Zohocorp Manageengine Access Manager Plus SQL Injection

  • CVSS 9.8

New critical Zohocorp Manageengine Access Manager Plus SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-45995 CVSS 9.8

There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn.

CVE-2022-47523 CVSS 9.8

Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Inject...

CVE-2022-47544 CVSS 9.8

An issue was discovered in Siren Investigate before 12.1.7.

View critical disclosures

cvelogic Threat Intelligence