May 5, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2016-20010 Ewww Image Optimizer

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2021-31800 Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22.

  • CVSS 9.8
  • Remote code execution exposure

New critical Fedoraproject Fedora RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-13665 Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2016-20010 CVSS 10

EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is...

CVE-2020-13665 CVSS 9.8

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode.

CVE-2020-36333 CVSS 9.1

themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

CVE-2020-4979 CVSS 9.8

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication.

CVE-2021-31800 CVSS 9.8

Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22.

CVE-2021-32055 CVSS 9.1

Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an...

View critical disclosures

cvelogic Threat Intelligence