Jan 4, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-21643 USOC is an open source CMS with a focus on simplicity.

  • CVSS 10

New critical Useful Simple Open-source Cms Project Useful Simple Open-source Cms SQL Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-43832 Spinnaker is an open source, multi-cloud continuous delivery platform.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2021-24042 Whatsapp Out-of-Bounds Write

  • CVSS 9.8

New critical Whatsapp Out-of-Bounds Write (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-24042 CVSS 9.8

The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to...

CVE-2021-40525 CVSS 9.1

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing read...

CVE-2021-43711 CVSS 9.8

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET param...

CVE-2021-43832 CVSS 10

Spinnaker is an open source, multi-cloud continuous delivery platform.

CVE-2022-0086 CVSS 9.8

uppy is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2022-21643 CVSS 10

USOC is an open source CMS with a focus on simplicity.

CVE-2022-21644 CVSS 9.1

USOC is an open source CMS with a focus on simplicity.

View critical disclosures

cvelogic Threat Intelligence