Jun 16, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Open-emr Openemr: public exploit or PoC linked (Auth Bypass)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2018-15152 Open-emr Openemr Auth Bypass

  • Public exploit or PoC available
  • Exploit activity linked
  • Authentication bypass — unauthenticated access risk

Open-emr Openemr Auth Bypass now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2020-22204 SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php.

  • CVSS 9.8

New critical Shopex Ecshop SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-22205 SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.

  • CVSS 9.8

New critical Shopex Ecshop SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2018-15152 Exploit

Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to acce...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-22204 CVSS 9.8

SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php.

CVE-2020-22205 CVSS 9.8

SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.

CVE-2020-22206 CVSS 9.8

SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.

CVE-2020-22208 CVSS 9.8

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

CVE-2020-22209 CVSS 9.8

SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.

CVE-2020-22210 CVSS 9.8

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

CVE-2020-22211 CVSS 9.8

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CVE-2020-22212 CVSS 9.8

SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.

CVE-2020-25753 CVSS 9.8

An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software.

CVE-2021-34813 CVSS 9.8

Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted ro...

View critical disclosures

cvelogic Threat Intelligence