Jun 18, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Node-serialize Project Node-serialize: public exploit or PoC linked (RCE)
  • 4 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2017-5941 An issue was discovered in the node-serialize package 0.0.4 for Node.js.

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Node-serialize Project Node-serialize RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-21669 Jenkins Generic Webhook Trigger XXE

  • CVSS 9.8

New critical Jenkins Generic Webhook Trigger XXE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-31272 Serenityos Directory Traversal

  • CVSS 9.8

New critical Serenityos Directory Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2017-5941 Exploit

An issue was discovered in the node-serialize package 0.0.4 for Node.js.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-21669 CVSS 9.8

Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVE-2021-31272 CVSS 9.8

SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead...

CVE-2021-33576 CVSS 9.8

An issue was discovered in Cleo LexiCom 5.5.0.0.

CVE-2021-3604 CVSS 9.8

Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection.

View critical disclosures

cvelogic Threat Intelligence