Nov 23, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Softwell Webrun: public exploit or PoC linked (SQL Injection)
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2019-13272 Linux Kernel Improper Privilege Management

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Linux Kernel privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2021-43650 Softwell Webrun SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked

Softwell Webrun SQL Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-37022 Huawei Harmonyos Buffer Overflow

  • CVSS 9.8

New critical Huawei Harmonyos Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-43650 Exploit

WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-36312 CVSS 9.1

Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability.

CVE-2021-36313 CVSS 9.1

Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability.

CVE-2021-37016 CVSS 9.1

There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Dis...

CVE-2021-37022 CVSS 9.8

There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root pe...

CVE-2021-38002 CVSS 9.6

Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape...

CVE-2021-42783 CVSS 9.8

Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated...

CVE-2021-42784 CVSS 9.8

OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform command injection via...

CVE-2021-42785 CVSS 9.8

Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafte...

View critical disclosures

cvelogic Threat Intelligence