Dec 14, 2021 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Apache Log4j2: public exploit or PoC linked (RCE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-44228 Apache Log4j2 Remote Code Execution

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Apache Log4j2 RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2019-9581 Twinkletoessoftware Booked

  • Public exploit or PoC available
  • Exploit activity linked

Public exploit or PoC linked — exploitation bar is lower than disclosure-only CVEs.

Critical exposure

CVE-2021-43821 Opencast is an Open Source Lecture Capture & Video Management for Education.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2019-9581 Exploit

phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-fav...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-4073 CVSS 9.8

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, i...

CVE-2021-40883 CVSS 9.8

A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.

CVE-2021-42064 CVSS 9.8

If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SA...

CVE-2021-43821 CVSS 9.9

Opencast is an Open Source Lecture Capture & Video Management for Education.

CVE-2021-44041 CVSS 9.8

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the UR...

CVE-2021-44042 CVSS 9.8

An issue was discovered in UiPath Assistant 21.4.4.

CVE-2021-44231 CVSS 9.8

Internally used text extraction reports allow an attacker to inject code that can be executed by the application.

CVE-2021-44949 CVSS 9.8

glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.

CVE-2021-45015 CVSS 9.1

taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72.

Apache Log4j2 Deserialization of Untrusted Data

View critical disclosures

cvelogic Threat Intelligence