Dec 7, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2021-24041 Whatsapp Out-of-Bounds Write

  • CVSS 9.8

New critical Whatsapp Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-37095 Huawei Harmonyos RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Huawei Harmonyos RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-38759 Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Raspberrypi Raspberry Pi Os Lite privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-24041 CVSS 9.8

A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could...

CVE-2021-37079 CVSS 9.1

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete...

CVE-2021-37084 CVSS 9.8

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicio...

CVE-2021-37087 CVSS 9.1

There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can crea...

CVE-2021-37088 CVSS 9.1

There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can writ...

CVE-2021-37095 CVSS 9.8

There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to re...

CVE-2021-37099 CVSS 9.1

There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file.

CVE-2021-38759 CVSS 9.8

Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.

CVE-2021-40859 CVSS 9.8

Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management...

CVE-2021-41716 CVSS 9.8

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fix...

View critical disclosures

cvelogic Threat Intelligence