Feb 6, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-31573 In Config Manager, there is a possible command injection due to improper input validation.

  • CVSS 9.8

New critical Mediatek En7528 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-31574 In Config Manager, there is a possible command injection due to improper input validation.

  • CVSS 9.8

New critical Mediatek En7528 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-31575 In Config Manager, there is a possible command injection due to improper input validation.

  • CVSS 9.8

New critical Mediatek En7528 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-31573 CVSS 9.8

In Config Manager, there is a possible command injection due to improper input validation.

CVE-2021-31574 CVSS 9.8

In Config Manager, there is a possible command injection due to improper input validation.

CVE-2021-31575 CVSS 9.8

In Config Manager, there is a possible command injection due to improper input validation.

CVE-2021-31577 CVSS 9.8

In Boa, there is a possible escalation of privilege due to a missing permission check.

CVE-2021-31578 CVSS 9.8

In Boa, there is a possible escalation of privilege due to a stack buffer overflow.

CVE-2022-3229 CVSS 9.8

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unaut...

CVE-2022-4681 CVSS 9.8

The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an...

CVE-2022-47071 CVSS 9.8

In NVS365 V01, the background network test function can trigger command execution.

**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Mode...

CVE-2023-23333 CVSS 9.8

There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restri...

View critical disclosures

cvelogic Threat Intelligence