Oct 19, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Myfactory Fms: public exploit or PoC linked (cross-site scripting)
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-24719 Kriesi Enfold XSS

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2021-42565 myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

  • Public exploit or PoC available
  • Exploit activity linked

Myfactory Fms cross-site scripting now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-30820 A logic issue was addressed with improved state management.

  • CVSS 9.8
  • Remote code execution exposure

New critical Apple Ipados RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-42565 Exploit

myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

CVE-2021-42566 Exploit

myfactory.FMS before 7.1-912 allows XSS via the Error parameter.

CVE-2021-24719 Exploit

The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS).

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-12141 CVSS 9.1

An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially dis...

CVE-2021-30820 CVSS 9.8

A logic issue was addressed with improved state management.

CVE-2021-31349 CVSS 9.8

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal file...

CVE-2021-38462 CVSS 9.8

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy.

CVE-2021-38470 CVSS 9.1

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands in...

CVE-2021-38478 CVSS 9.1

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject comma...

CVE-2021-38480 CVSS 9.6

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized comman...

CVE-2021-38484 CVSS 9.1

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an uploa...

View critical disclosures

cvelogic Threat Intelligence