Nov 29, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 6 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-24915 Contest Gallery SQL Injection

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Contest Gallery SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-44427 Rosariosis SQL Injection

  • CVSS 9.8

New critical Rosariosis SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-43691 Tripexpress Project Tripexpress

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-24915 CVSS 9.8

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-n...

CVE-2021-43691 CVSS 9.8

tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php.

CVE-2021-43693 CVSS 9.8

vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.

CVE-2021-43786 CVSS 9.8

Nodebb is an open source Node.js based forum software.

Nodebb is an open source Node.js based forum software.

CVE-2021-44427 CVSS 9.8

An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attacker...

View critical disclosures

cvelogic Threat Intelligence