May 3, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Piwigo: public exploit or PoC linked (SQL Injection)
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-27973 SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

  • Public exploit or PoC available
  • Exploit activity linked

Piwigo SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2020-23083 Guojusoft Jeecg privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Guojusoft Jeecg privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-35758 An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices.

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Librewireless Ls9 Firmware Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-27973 Exploit

SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-23083 CVSS 9.8

Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a cr...

CVE-2020-35757 CVSS 9.8

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices.

CVE-2020-35758 CVSS 9.8

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices.

CVE-2021-28860 CVSS 9.1

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge()...

CVE-2021-29369 CVSS 9.8

The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.

CVE-2021-32020 CVSS 9.8

The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.

View critical disclosures

cvelogic Threat Intelligence