NVD disclosure day

Published threat advisories for April 26, 2022

CVE advisoryCRITICAL

CVE-2022-27984

CuppaCMS SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in CuppaCMS allows unauthenticated attackers to manipulate database queries over a network. This could lead to unauthorized access or modification of sensitive data if the system is reachable. The relevance and exposure of any CuppaCMS installations should be confirmed.

CVE advisoryKnown Exploit

CVE-2022-24706

Apache CouchDB Default Installation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improperly secured default installation of Apache CouchDB allows unauthenticated attackers to gain administrative privileges, impacting organizations using the database. This exposes them to risks of unauthorized data access and control, necessitating immediate security configuration reviews and updates.

• CISA KEV