Jun 30, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2018-25017 RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.

  • CVSS 9.8

New critical Rawspeed Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-36400 Zeromq Libzmq Buffer Overflow

  • CVSS 9.8

New critical Zeromq Libzmq Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-22345 There is an Input Verification Vulnerability in Huawei Smartphone.

  • CVSS 9.8

New critical Huawei Emui Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-25017 CVSS 9.8

RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.

CVE-2020-36400 CVSS 9.8

ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.

CVE-2021-22345 CVSS 9.8

There is an Input Verification Vulnerability in Huawei Smartphone.

CVE-2021-22348 CVSS 9.8

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.

CVE-2021-22354 CVSS 9.1

There is an Information Disclosure Vulnerability in Huawei Smartphone.

CVE-2021-22367 CVSS 9.8

There is a Key Management Errors Vulnerability in Huawei Smartphone.

CVE-2021-28802 CVSS 9.8

A command injection vulnerabilities have been reported to affect QTS and QuTS hero.

CVE-2021-28804 CVSS 9.8

A command injection vulnerabilities have been reported to affect QTS and QuTS hero.

CVE-2021-35973 CVSS 9.8

NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauth...

CVE-2021-36088 CVSS 9.8

Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).

View critical disclosures

cvelogic Threat Intelligence