Mar 28, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Reqlogic: public exploit or PoC linked (XSS)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-32272 Opswat Metadefender Privilege Escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Opswat Metadefender Privilege Escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-36551 Heartex Label Studio SSRF

  • Public exploit or PoC available
  • Exploit activity linked

Heartex Label Studio SSRF now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-45460 Xiongmaitech Mbd6304t Firmware Buffer Overflow

  • CVSS 9.8

New critical Xiongmaitech Mbd6304t Firmware Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-37255 Exploit

TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.

CVE-2022-41441 Exploit

Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a craf...

CVE-2022-42953 Exploit

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the f...

CVE-2022-38580 Exploit

Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

CVE-2022-3552 Exploit

Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.

CVE-2022-36551 Exploit

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier all...

CVE-2022-24082 Exploit

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port fil...

CVE-2022-32272 Exploit

OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorre...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-24673 CVSS 9.8

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers.

CVE-2022-45460 CVSS 9.8

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.0...

CVE-2022-46387 CVSS 9.8

ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to...

CVE-2023-27229 CVSS 9.8

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/set...

CVE-2023-27231 CVSS 9.8

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/s...

CVE-2023-27232 CVSS 9.8

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /sett...

CVE-2023-27394 CVSS 9.8

Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability.

CVE-2023-27886 CVSS 9.8

Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability.

CVE-2023-28398 CVSS 9.8

Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining u...

CVE-2023-28654 CVSS 9.8

Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the we...

View critical disclosures

cvelogic Threat Intelligence