Jul 30, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-34165 Basic Shopping Cart Project Basic Shopping Cart SQL Injection

  • CVSS 9.8

New critical Basic Shopping Cart Project Basic Shopping Cart SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-34166 Simple Food Website Project Simple Food Website SQL Injection

  • CVSS 9.8

New critical Simple Food Website Project Simple Food Website SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-35458 Online Pet Shop We App Project Online Pet Shop We App SQL Injection

  • CVSS 9.8

New critical Online Pet Shop We App Project Online Pet Shop We App SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-25200 CVSS 9.8

Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via th...

CVE-2021-30124 CVSS 9.8

The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbi...

CVE-2021-34165 CVSS 9.8

A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.

CVE-2021-34166 CVSS 9.8

A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.

CVE-2021-35458 CVSS 9.8

Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.

CVE-2021-36624 CVSS 9.8

Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authenti...

CVE-2021-37144 CVSS 9.1

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.

CVE-2021-37593 CVSS 9.1

PEEL Shopping version 9.4.0 allows remote SQL injection.

CVE-2021-37594 CVSS 9.8

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a...

CVE-2021-37595 CVSS 9.8

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a...

View critical disclosures

cvelogic Threat Intelligence