Jan 27, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-44298 SiteServer CMS 7.1.3 is vulnerable to SQL Injection.

  • CVSS 9.8

New critical Sscms Siteserver Cms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-48011 Opencats SQL Injection

  • CVSS 9.8

New critical Opencats SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-48107 Dlink Dir 878 Firmware Command Injection

  • CVSS 9.8

New critical Dlink Dir 878 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-39811 CVSS 9.1

Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader.

CVE-2022-44298 CVSS 9.8

SiteServer CMS 7.1.3 is vulnerable to SQL Injection.

CVE-2022-48008 CVSS 9.8

An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a craft...

CVE-2022-48011 CVSS 9.8

Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

CVE-2022-48066 CVSS 9.8

An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.

CVE-2022-48107 CVSS 9.8

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress.

CVE-2022-48108 CVSS 9.8

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask.

CVE-2023-0556 CVSS 9.8

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in ve...

View critical disclosures

cvelogic Threat Intelligence