Jul 1, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Xcloner: public exploit or PoC linked (RCE)
  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2020-35948 An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress.

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Critical exposure

CVE-2018-25017 RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.

  • CVSS 9.8

New critical Rawspeed Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-36400 Zeromq Libzmq Buffer Overflow

  • CVSS 9.8

New critical Zeromq Libzmq Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2020-35948 Exploit

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-25017 CVSS 9.8

RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.

CVE-2020-36400 CVSS 9.8

ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.

CVE-2021-22343 CVSS 9.1

There is a Configuration Defect vulnerability in Huawei Smartphone.

CVE-2021-28802 CVSS 9.8

A command injection vulnerabilities have been reported to affect QTS and QuTS hero.

CVE-2021-28804 CVSS 9.8

A command injection vulnerabilities have been reported to affect QTS and QuTS hero.

CVE-2021-35336 CVSS 9.8

Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control.

CVE-2021-36088 CVSS 9.8

Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).

View critical disclosures

cvelogic Threat Intelligence