Jan 12, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Frontend Uploader Project Frontend Uploader: public exploit or PoC linked

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-24563 Frontend Uploader Project Frontend Uploader

  • Public exploit or PoC available
  • Exploit activity linked
  • Internet-facing CMS deployments affected

WordPress plugin exposure with public exploit material — mass targeting of internet-facing CMS installs is common once PoCs circulate.

Critical exposure

CVE-2022-21675 Bytecode Viewer (BCV) is a Java/Android reverse engineering suite.

  • CVSS 9.9

New critical Bytecode Viewer Project Bytecode Viewer Directory Traversal (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-45411 Printable Staff Id Card Creator System Project Printable Staff Id Card Creator System RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Printable Staff Id Card Creator System Project Printable Staff Id Card Creator System RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2021-24563 Exploit

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticat...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-45411 CVSS 9.8

In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and lever...

CVE-2022-21675 CVSS 9.9

Bytecode Viewer (BCV) is a Java/Android reverse engineering suite.

View critical disclosures

cvelogic Threat Intelligence