Nov 22, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-3943 Moodle RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Moodle RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-44079 Wazuh RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Wazuh RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-44143 A flaw was found in mbsync in isync 1.4.0 through 1.4.3.

  • CVSS 9.8
  • Remote code execution exposure

New critical Debian Linux RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

This affects all versions of package docker-cli-js.

CVE-2021-3943 CVSS 9.8

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions.

CVE-2021-44079 CVSS 9.8

In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potential...

CVE-2021-44143 CVSS 9.8

A flaw was found in mbsync in isync 1.4.0 through 1.4.3.

CVE-2021-44144 CVSS 9.1

Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date.

View critical disclosures

cvelogic Threat Intelligence