May 26, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Pluck-cms Pluck: public exploit or PoC linked (RCE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2020-29607 Pluck-cms Pluck RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Pluck-cms Pluck RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2015-3306 Proftpd

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2019-25029 Versa-networks Versa Director Command Injection

  • CVSS 9.8

New critical Versa-networks Versa Director Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2020-29607 Exploit

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host thro...

CVE-2018-19423 Exploit

Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.

CVE-2015-3306 Exploit

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-10866 CVSS 9.1

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthe...

CVE-2018-10867 CVSS 9.1

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove...

CVE-2019-25029 CVSS 9.8

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system v...

CVE-2021-20487 CVSS 9.1

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware...

CVE-2021-21986 CVSS 9.8

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery...

CVE-2021-22731 CVSS 9.8

Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prio...

CVE-2021-22737 CVSS 9.8

Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unau...

CVE-2021-22738 CVSS 9.8

Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that coul...

CVE-2021-25945 CVSS 9.8

Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead t...

CVE-2021-33470 CVSS 9.8

COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.

View critical disclosures

cvelogic Threat Intelligence