NVD disclosure day

Published threat advisories for March 10, 2022

CVE advisoryKnown Exploit

CVE-2022-26143

Mitel MiCollab and MiVoice Business Express Information Disclosure and Denial of Service Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Mitel MiCollab and MiVoice Business Express affects the TP-240 component. This flaw allows unauthorized access to sensitive information and can cause denial of service. The risk to organizations includes data exposure and service disruption.

• CISA KEV

CVE advisoryCRITICAL

CVE-2022-23383

YzmCMS v6.3 Unauthorized Access to User Home Pages

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical broken access control vulnerability exists in YzmCMS v6.3, allowing unauthenticated users to access personal home pages, potentially exposing other users' information. This issue arises from insufficient authentication checks before granting access to user-specific pages.