Jul 2, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Nica Winwaste.net: public exploit or PoC linked (privilege escalation)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-34110 Nica Winwaste.net privilege escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Nica Winwaste.net privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2021-35956 Akcp Sensorprobe2 Firmware XSS

  • Public exploit or PoC available
  • Exploit activity linked

Akcp Sensorprobe2 Firmware XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-35029 Zyxel Usg1000 Firmware Auth Bypass

  • CVSS 9.8
  • Authentication bypass — unauthenticated access risk

New critical Zyxel Usg1000 Firmware Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-34110 Exploit

WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malici...

CVE-2021-35956 Exploit

Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attack...

CVE-2021-24145 Exploit

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported fi...

CVE-2021-24146 Exploit

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict acces...

CVE-2020-7750 Exploit

This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-35029 CVSS 9.8

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4...

CVE-2021-35042 CVSS 9.8

Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of...

CVE-2021-35209 CVSS 9.8

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x befor...

CVE-2021-36126 CVSS 9.8

An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36.

CVE-2021-36128 CVSS 9.8

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.

View critical disclosures

cvelogic Threat Intelligence