Aug 16, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2020-18701 Talelin Lin-cms-flask privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Talelin Lin-cms-flask privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-18703 Quokka Project Quokka XXE

  • CVSS 9.8

New critical Quokka Project Quokka XXE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-18705 Quokka Project Quokka XXE

  • CVSS 9.8

New critical Quokka Project Quokka XXE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-18698 CVSS 9.8

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the...

CVE-2020-18701 CVSS 9.8

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to th...

CVE-2020-18703 CVSS 9.8

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.

CVE-2020-18704 CVSS 9.8

Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image'...

CVE-2020-18705 CVSS 9.8

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/vie...

CVE-2021-22931 CVSS 9.8

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validat...

CVE-2021-38753 CVSS 9.8

An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized acce...

CVE-2021-38754 CVSS 9.8

SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.

View critical disclosures

cvelogic Threat Intelligence