Jun 11, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Cerberusftp Ftp Server: public exploit or PoC linked (cross-site scripting)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2017-9380 Open-emr Openemr RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Open-emr Openemr RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2019-25046 Cerberusftp Ftp Server cross-site scripting

  • Public exploit or PoC available
  • Exploit activity linked

Cerberusftp Ftp Server cross-site scripting now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-34679 Thycotic Password Reset Server before 5.3.0 allows credential disclosure.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2019-25046 Exploit

The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.

CVE-2021-31950 Exploit

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2021-33904 Exploit

In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS.

CVE-2021-24174 Exploit

The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted act...

CVE-2017-9380 Exploit

OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-0474 CVSS 9.8

In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow.

CVE-2021-21795 CVSS 9.8

A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9.

CVE-2021-21824 CVSS 9.8

An out-of-bounds write vulnerability exists in the JPG Handle_JPEG420 functionality of Accusoft ImageGear 19.9.

CVE-2021-21833 CVSS 9.8

An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9.

CVE-2021-23140 CVSS 9.9

Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Comm...

CVE-2021-23230 CVSS 9.9

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to...

CVE-2021-27200 CVSS 9.8

In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php.

CVE-2021-27410 CVSS 9.8

The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn...

CVE-2021-32930 CVSS 9.8

The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations an...

CVE-2021-34679 CVSS 10

Thycotic Password Reset Server before 5.3.0 allows credential disclosure.

View critical disclosures

cvelogic Threat Intelligence