Nov 1, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-20136 Zohocorp Manageengine Log360 RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Zohocorp Manageengine Log360 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-26739 Doyocms Project Doyocms SQL Injection

  • CVSS 9.8

New critical Doyocms Project Doyocms SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-29212 Hp Ilo Amplifier Pack Directory Traversal

  • CVSS 9.8

New critical Hp Ilo Amplifier Pack Directory Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-20136 CVSS 9.8

ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite.

CVE-2021-26739 CVSS 9.8

SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.

CVE-2021-26740 CVSS 9.8

Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.

CVE-2021-29212 CVSS 9.8

A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1....

CVE-2021-3705 CVSS 9.8

Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow an unauthorized user to recon...

View critical disclosures

cvelogic Threat Intelligence