Jan 5, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Solari Termtalk Server: public exploit or PoC linked (Directory Traversal)

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-24750 Codepress Visitor Statistics SQL Injection

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Active exploit activity

CVE-2021-35380 Solari Termtalk Server Directory Traversal

  • Public exploit or PoC available
  • Exploit activity linked

Solari Termtalk Server Directory Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-43779 GLPI is an open source IT Asset Management, issue tracking system and service desk system.

  • CVSS 9.9
  • Remote code execution exposure

New critical Teclib-edition Addressing RCE (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-35380 Exploit

A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated maliciou...

CVE-2021-45425 Exploit

Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.

CVE-2021-45814 Exploit

Nettmp NNT 5.1 is affected by a SQL injection vulnerability.

CVE-2021-43857 Exploit

Gerapy is a distributed crawler management framework.

CVE-2021-24750 Exploit

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDeta...

CVE-2021-43326 Exploit

Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.

CVE-2021-39312 Exploit

The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to b...

CVE-2019-16516 Exploit

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-41842 CVSS 9.8

An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46,...

CVE-2021-43779 CVSS 9.9

GLPI is an open source IT Asset Management, issue tracking system and service desk system.

View critical disclosures

cvelogic Threat Intelligence