Jan 24, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2020-17383 Telosalliance Z\/ip One Firmware Directory Traversal

  • CVSS 9.8

New critical Telosalliance Z\/ip One Firmware Directory Traversal (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-41471 South Gate Inn Online Reservation System Project South Gate Inn Online Reservation System SQL Injection

  • CVSS 9.8

New critical South Gate Inn Online Reservation System Project South Gate Inn Online Reservation System SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-41472 Simple Membership System Using Php And Ajax Project Simple Membership System Using Php And Ajax SQL Injection

  • CVSS 9.8

New critical Simple Membership System Using Php And Ajax Project Simple Membership System Using Php And Ajax SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-17383 CVSS 9.8

A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to th...

CVE-2021-41471 CVSS 9.8

SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbit...

CVE-2021-41472 CVSS 9.8

SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL command...

CVE-2021-41659 CVSS 9.8

SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the...

CVE-2021-41660 CVSS 9.8

SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary...

CVE-2021-41928 CVSS 9.8

SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code...

CVE-2021-43394 CVSS 9.8

Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authenticatio...

CVE-2021-43420 CVSS 9.8

SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL...

CVE-2021-46451 CVSS 9.8

An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file f...

CVE-2022-23126 CVSS 9.8

TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Dri...

View critical disclosures

cvelogic Threat Intelligence