Oct 27, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-38450 The affected controllers do not properly sanitize the input containing code syntax.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2011-4124 Calibre-ebook Calibre privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Calibre-ebook Calibre privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2011-4125 Calibre-ebook Calibre privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Calibre-ebook Calibre privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2011-4124 CVSS 9.8

Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privi...

CVE-2011-4125 CVSS 9.8

A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execut...

CVE-2011-4574 CVSS 9.8

PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm.

CVE-2020-21250 CVSS 9.8

CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.

CVE-2020-24932 CVSS 9.8

An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

CVE-2021-38450 CVSS 9.9

The affected controllers do not properly sanitize the input containing code syntax.

CVE-2021-41589 CVSS 9.8

In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code exec...

View critical disclosures

cvelogic Threat Intelligence