Apr 26, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Seopanel Seo Panel: public exploit or PoC linked (SQL Injection)
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-28419 Seopanel Seo Panel SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked

Seopanel Seo Panel SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-29475 HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2021-25927 Safe-flat Project Safe-flat RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Safe-flat Project Safe-flat RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-28419 Exploit

The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability t...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-21201 CVSS 9.6

Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process t...

CVE-2021-21223 CVSS 9.6

Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to pot...

CVE-2021-21226 CVSS 9.6

Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to...

CVE-2021-25839 CVSS 9.8

A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker t...

CVE-2021-25927 CVSS 9.8

Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lea...

CVE-2021-25928 CVSS 9.8

Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead...

CVE-2021-26797 CVSS 9.8

An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an o...

CVE-2021-29475 CVSS 10

HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor.

CVE-2021-31646 CVSS 9.8

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote).

View critical disclosures

cvelogic Threat Intelligence