Aug 4, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Apache Ofbiz: public exploit or PoC linked (XSS)
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2020-7246 A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Qdpm RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2020-9496 Apache Ofbiz XSS

  • Public exploit or PoC available
  • Exploit activity linked

Apache Ofbiz XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-32590 Fortinet Fortiportal SQL injection

  • CVSS 9.9

New critical Fortinet Fortiportal SQL injection (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2020-9496 Exploit

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

CVE-2020-7246 Exploit

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-1609 CVSS 9.8

Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Giga...

CVE-2021-1610 CVSS 9.8

Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Giga...

CVE-2021-20028 CVSS 9.8

SonicWall Secure Remote Access (SRA) SQL Injection

CVE-2021-32590 CVSS 9.9

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 thr...

CVE-2021-37232 CVSS 9.8

A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due to the lack of b...

View critical disclosures

cvelogic Threat Intelligence