Mar 23, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Guralp Man-eam-0003: public exploit or PoC linked (XXE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-35583 Wkhtmltopdf SSRF

  • Public exploit or PoC available
  • Exploit activity linked

Wkhtmltopdf SSRF now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-36804 Atlassian Bitbucket Server and Data Center Command Injection

  • Public exploit or PoC available
  • Exploit activity linked

Atlassian Bitbucket Server And Data Center Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-28496 Totolink Cp900 Firmware Command Injection

  • CVSS 9.8

New critical Totolink Cp900 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-38840 Exploit

cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads t...

CVE-2022-36804 Exploit

Atlassian Bitbucket Server and Data Center Command Injection

CVE-2022-35583 Exploit

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-28496 CVSS 9.8

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via...

CVE-2022-28497 CVSS 9.8

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader fun...

CVE-2022-36413 CVSS 9.1

Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.

CVE-2023-26359 CVSS 9.8

Adobe ColdFusion Deserialization of Untrusted Data

CVE-2023-27034 CVSS 9.8

PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

CVE-2023-28333 CVSS 9.8

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implem...

CVE-2023-28610 CVSS 9.8

The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update...

CVE-2023-28611 CVSS 9.8

Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intende...

View critical disclosures

cvelogic Threat Intelligence