Jan 23, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Zoho ManageEngine added to CISA KEV — confirmed in-the-wild exploitation.
  • WordPress plugin RCE/exploit activity: 4 CVEs flagged today.
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2022-47966 Zoho ManageEngine Multiple Products Remote Code Execution

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Zoho ManageEngine RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2022-4305 Wp-buy Login As User Or Customer \(user Switching\) privilege escalation

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Wp-buy Login As User Or Customer \(user Switching\) privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-4383 Codeboxr Cbx Petition For Wordpress SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Codeboxr Cbx Petition For Wordpress SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Zoho ManageEngine Multiple Products Remote Code Execution

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-43445 CVSS 9.8

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.

CVE-2022-0316 CVSS 9.8

The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme Word...

CVE-2022-4305 CVSS 9.8

The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as anothe...

CVE-2022-4383 CVSS 9.8

The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement...

CVE-2022-4693 CVSS 9.8

The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability.

CVE-2023-23560 CVSS 9.8

In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.

View critical disclosures

cvelogic Threat Intelligence