Oct 11, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2020-27372 Brandy Project Brandy Buffer Overflow

  • CVSS 9.8

New critical Brandy Project Brandy Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-40239 Miniftpd Project Miniftpd Buffer Overflow

  • CVSS 9.8

New critical Miniftpd Project Miniftpd Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-40543 Os4ed Opensis SQL Injection

  • CVSS 9.8

New critical Os4ed Opensis SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-27372 CVSS 9.8

A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.

CVE-2021-26588 CVSS 9.8

A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firm...

CVE-2021-27664 CVSS 9.8

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

CVE-2021-37123 CVSS 9.8

There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200.

CVE-2021-40239 CVSS 9.8

A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c

CVE-2021-40543 CVSS 9.8

Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_...

CVE-2021-40617 CVSS 9.8

An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.

CVE-2021-40887 CVSS 9.8

Projectsend version r1295 is affected by a directory traversal vulnerability.

CVE-2021-40889 CVSS 9.8

CMSUno version 1.7.2 is affected by a PHP code execution vulnerability.

CVE-2021-42139 CVSS 9.8

Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.

View critical disclosures

cvelogic Threat Intelligence