Dec 30, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

High-risk exposure

CVE-2022-50794 Sound4 Big Voice2 Firmware Command Injection

  • CVSS 9.3

New high-severity Sound4 Big Voice2 Firmware Command Injection — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

High-risk exposure

CVE-2022-50796 Sound4 Big Voice2 Firmware RCE

  • CVSS 9.3
  • Remote code execution exposure

New high-severity Sound4 Big Voice2 Firmware RCE — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

High-risk exposure

CVE-2023-54327 Tinycontrol Lan Controller Firmware Auth Bypass

  • CVSS 9.3
  • Authentication bypass — unauthenticated access risk

New high-severity Tinycontrol Lan Controller Firmware Auth Bypass — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-50691 CVSS 9.3

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as...

CVE-2022-50696 CVSS 9.3

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified th...

CVE-2022-50794 CVSS 9.3

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter.

CVE-2022-50796 CVSS 9.3

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality...

CVE-2022-50803 CVSS 9.3

JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administ...

CVE-2023-53983 CVSS 9.3

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed.

CVE-2023-54327 CVSS 9.3

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin pa...

CVE-2025-15111 CVSS 9.3

Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain...

CVE-2025-15113 CVSS 9.3

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated...

CVE-2025-15114 CVSS 9.3

Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in t...

View critical disclosures

cvelogic Threat Intelligence