Feb 22, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2023-25813 Sequelize is a Node.js ORM tool.

  • CVSS 10

New critical Sequelizejs Sequelize SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-45599 Aztech Wmb250ac Firmware privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Aztech Wmb250ac Firmware privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-48149 Online Student Admission System Project Online Student Admission System SQL Injection

  • CVSS 9.8

New critical Online Student Admission System Project Online Student Admission System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-39983 CVSS 9.8

File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute ar...

CVE-2022-41217 CVSS 9.8

Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the...

CVE-2022-45599 CVSS 9.8

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to...

CVE-2022-48149 CVSS 9.8

Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username para...

CVE-2023-0104 CVSS 9.3

The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file.

CVE-2023-24093 CVSS 9.8

An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.

CVE-2023-24114 CVSS 9.8

typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

View critical disclosures

cvelogic Threat Intelligence