Dec 2, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-28237 LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.

  • CVSS 9.8

New critical Gnu Libredwg Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-43679 Shopex Ecshop SQL Injection

  • CVSS 9.8

New critical Shopex Ecshop SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2015-20105 Cbads Clickbank Affiliate Ads XSS

  • CVSS 9.6
  • Internet-facing CMS deployments affected

New critical Cbads Clickbank Affiliate Ads XSS (CVSS 9.6) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2015-20105 CVSS 9.6

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make lo...

CVE-2020-29177 CVSS 9.1

Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.

CVE-2021-28237 CVSS 9.8

LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.

Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Commu...

CVE-2021-43679 CVSS 9.8

ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.

View critical disclosures

cvelogic Threat Intelligence