Jun 18, 2021 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- Node-serialize Project Node-serialize: public exploit or PoC linked (RCE)
- 4 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js.
- Public exploit or PoC available
- Exploit activity linked
- Remote code execution exposure
Node-serialize Project Node-serialize RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2021-21669
Jenkins Generic Webhook Trigger XXE
New critical Jenkins Generic Webhook Trigger XXE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2021-31272
Serenityos Directory Traversal
New critical Serenityos Directory Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploit & PoC activity
An issue was discovered in the node-serialize package 0.0.4 for Node.js.
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead...
An issue was discovered in Cleo LexiCom 5.5.0.0.
Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection.
View critical disclosures
cvelogic
Threat Intelligence