Weekly digest
Week 2, 2024 (8–14 Jan)
16 new CVEs this week, in line with the recent average. Severity skewed high: 4 critical and 6 high, 63% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-21887Critical· 9.1CISA KEV0dayPoCA command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
CVE-2023-46805High· 8.2CISA KEV0dayPoCAn authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CVE-2023-27524High· 8.9CISA KEVPoCApache superset missing check for default SECRET_KEY
Apache superset missing check for default SECRET_KEY
New this week, ranked by depth score
The 12 that matter most of the 16 published.
CVE-2024-21887Critical· 9.1CISA KEV0dayPoCA command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
CVE-2023-46805High· 8.2CISA KEV0dayPoCAn authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CVE-2024-21644High· 7.5PoCpyload Unauthenticated Flask Configuration Leakage vulnerability
pyload Unauthenticated Flask Configuration Leakage vulnerability
CVE-2022-2586Medium· 5.3CISA KEV0dayPoCIt was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
CVE-2024-21669Critical· 9.9Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
CVE-2023-49569Critical· 9.8Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
CVE-2024-22199Critical· 9.3Django Template Engine Vulnerable to XSS
Django Template Engine Vulnerable to XSS
CVE-2024-21645Medium· 5.3PoCpyload Log Injection vulnerability
pyload Log Injection vulnerability
CVE-2024-22190High· 7.8Untrusted search path under some conditions on Windows allows arbitrary code execution
Untrusted search path under some conditions on Windows allows arbitrary code execution
CVE-2023-52289High· 7.5Path traversal in flaskcode
Path traversal in flaskcode
CVE-2023-52288High· 7.5Path traversal in flaskcode
Path traversal in flaskcode
CVE-2023-45139High· 7.5fonttools XML External Entity Injection (XXE) Vulnerability
fonttools XML External Entity Injection (XXE) Vulnerability
Most-affected vendors
By CVEs published in the period.