Oct 7, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Google Slo Generator: public exploit or PoC linked (Code Execution)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-22557 Google Slo Generator Code Execution

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Google Slo Generator Code Execution now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2020-21725 Opensns SQL Injection

  • CVSS 9.8

New critical Opensns SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-21726 Opensns SQL Injection

  • CVSS 9.8

New critical Opensns SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-22557 Exploit

SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of th...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-21725 CVSS 9.8

OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid parameter.

CVE-2020-21726 CVSS 9.8

OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter.

CVE-2020-21865 CVSS 9.8

ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.

CVE-2021-38298 CVSS 9.8

Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.

CVE-2021-3833 CVSS 9.8

Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash sto...

CVE-2021-42071 CVSS 9.8

In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-b...

CVE-2021-42090 CVSS 9.8

An issue was discovered in Zammad before 4.1.1.

CVE-2021-42091 CVSS 9.1

An issue was discovered in Zammad before 4.1.1.

CVE-2021-42094 CVSS 9.8

An issue was discovered in Zammad before 4.1.1.

View critical disclosures

cvelogic Threat Intelligence