Weekly digest
Week 1, 2024 (1–7 Jan)
A heavy week: 34 new CVEs, well above the recent average of about 15. Of those, 4 critical and 8 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. paddlepaddle was the most-affected vendor with 18.
New this week, ranked by depth score
The 12 that matter most of the 34 published.
CVE-2024-21907High· 7.5PoCNewtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial…
CVE-2024-22051Critical· 9.8CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information lea…
CVE-2023-52314Critical· 9.6PaddlePaddle command injection in convert_shape_compare
PaddlePaddle command injection in convert_shape_compare
CVE-2023-52311Critical· 9.6PaddlePaddle command injection in _wget_download
PaddlePaddle command injection in _wget_download
CVE-2023-52310Critical· 9.6PaddlePaddle command injection in get_online_pass_interval
PaddlePaddle command injection in get_online_pass_interval
CVE-2023-52309High· 8.2PaddlePaddle heap buffer overflow in paddle.repeat_interleave
PaddlePaddle heap buffer overflow in paddle.repeat_interleave
CVE-2023-52307High· 8.2PaddlePaddle stack overflow in paddle.linalg.lu_unpack
PaddlePaddle stack overflow in paddle.linalg.lu_unpack
CVE-2023-52304High· 8.2PaddlePaddle stack overflow in paddle.searchsorted
PaddlePaddle stack overflow in paddle.searchsorted
CVE-2024-21642High· 7.5D-Tale server-side request forgery through Web uploads
D-Tale server-side request forgery through Web uploads
CVE-2024-22050High· 7.5Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.
Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.
CVE-2024-0241High· 7.5encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability
encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely…
CVE-2024-21909High· 7.5PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability
PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data to the DecodeFromBytes or other decoding mechanisms in Pet…
Most-affected vendors
By CVEs published in the period.