May 13, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Internet Explorer: public exploit or PoC linked (RCE)
  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2020-0674 Microsoft Internet Explorer Scripting Engine Memory Corruption

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Microsoft Internet Explorer RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2019-12725 Zeroshell 3.9.0 is prone to a remote command execution vulnerability.

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2021-20998 Wago 0852-0303 Firmware privilege escalation

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical Wago 0852-0303 Firmware privilege escalation (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2019-17026 Exploit

Mozilla Firefox And Thunderbird Type Confusion

CVE-2020-0674 Exploit

Microsoft Internet Explorer Scripting Engine Memory Corruption

CVE-2019-12725 Exploit

Zeroshell 3.9.0 is prone to a remote command execution vulnerability.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-20092 CVSS 9.8

File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and...

CVE-2020-28063 CVSS 9.8

A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.

CVE-2021-20998 CVSS 10

In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to cre...

CVE-2021-20999 CVSS 9.4

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally...

CVE-2021-32615 CVSS 9.8

Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.

CVE-2021-33026 CVSS 9.8

The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local...

View critical disclosures

cvelogic Threat Intelligence