Sep 23, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Codeinitiator Fitness Calculators: public exploit or PoC linked (XSS)
  • 9 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-24169 Algolplus Advanced Order Export For Woocommerce cross-site scripting

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2021-24272 Codeinitiator Fitness Calculators XSS

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Critical exposure

CVE-2021-34770 New critical Cisco Ios Xe DoS disclosed.

  • CVSS 10
  • Network edge / SD-WAN deployments affected

New critical Cisco Ios Xe DoS (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-40875 Exploit

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.

CVE-2021-24272 Exploit

The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and...

CVE-2021-24169 Exploit

This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-4690 CVSS 9.8

IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound au...

CVE-2021-1619 CVSS 9.8

New critical Cisco Ios Xe DoS disclosed.

CVE-2021-21913 CVSS 9.8

An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03.

CVE-2021-22945 CVSS 9.1

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already fr...

CVE-2021-26794 CVSS 9.8

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

CVE-2021-34727 CVSS 9.8

New critical Cisco Ios Xe Sd-wan Buffer Overflow disclosed.

View critical disclosures

cvelogic Threat Intelligence