Feb 1, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-2329 Schneider-electric Interactive Graphical Scada System RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Schneider-electric Interactive Graphical Scada System RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-24324 Schneider-electric Interactive Graphical Scada System RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Schneider-electric Interactive Graphical Scada System RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-42971 Schneider-electric Apc Easy Ups Online Monitoring Software RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Schneider-electric Apc Easy Ups Online Monitoring Software RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-2329 CVSS 9.8

A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service...

CVE-2022-24324 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially lea...

CVE-2022-42970 CVSS 9.8

A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires...

CVE-2022-42971 CVSS 9.8

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker...

CVE-2022-47003 CVSS 9.8

New critical Murasoftware Mura Cms exposure disclosed.

CVE-2022-47714 CVSS 9.8

Last Yard 22.09.8-1 does not enforce HSTS headers

CVE-2023-22501 CVSS 9.1

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate...

CVE-2023-23076 CVSS 9.8

OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

CVE-2023-24997 CVSS 9.8

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0...

View critical disclosures

cvelogic Threat Intelligence