VulnSea

Weekly digest

Week 2, 2024 (8–14 Jan)

16 new CVEs this week, in line with the recent average. Severity skewed high: 4 critical and 6 high, 63% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog.

16
New CVEs
4
Critical
3
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2024-21887Critical· 9.1CISA KEV0dayPoC
2y ago

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

▾ Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2023-46805High· 8.2CISA KEV0dayPoC
2y ago

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2024-21644High· 7.5PoC
2y ago

pyload Unauthenticated Flask Configuration Leakage vulnerability

pyload Unauthenticated Flask Configuration Leakage vulnerability

▾ Midnightpyload-ng · pyload-ngEPSS 42%via OSV
CVE-2022-2586Medium· 5.3CISA KEV0dayPoC
2y ago

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

▾ Midnightlinux · linux_kernelEPSS 10%via NVD
CVE-2024-21669Critical· 9.9
2y ago

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

▾ Midnightaries-cloudagent · aries-cloudagentEPSS 0.63%via OSV
CVE-2023-49569Critical· 9.8
2y ago

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

▾ Midnightgo-git · github.com/go-git/go-git/v5EPSS 1.5%via OSV
CVE-2024-22199Critical· 9.3
2y ago

Django Template Engine Vulnerable to XSS

Django Template Engine Vulnerable to XSS

▾ Midnightgofiber · github.com/gofiber/template/django/v3EPSS 0.48%via OSV
CVE-2024-21645Medium· 5.3PoC
2y ago

pyload Log Injection vulnerability

pyload Log Injection vulnerability

▾ Twilightpyload-ng · pyload-ngEPSS 25%via OSV
CVE-2024-22190High· 7.8
2y ago

Untrusted search path under some conditions on Windows allows arbitrary code execution

Untrusted search path under some conditions on Windows allows arbitrary code execution

▾ Twilightgitpython · gitpythonEPSS 0.32%via OSV
CVE-2023-52289High· 7.5
2y ago

Path traversal in flaskcode

Path traversal in flaskcode

▾ Twilightflaskcode · flaskcodeEPSS 0.72%via OSV
CVE-2023-52288High· 7.5
2y ago

Path traversal in flaskcode

Path traversal in flaskcode

▾ Twilightflaskcode · flaskcodeEPSS 0.80%via OSV
CVE-2023-45139High· 7.5
2y ago

fonttools XML External Entity Injection (XXE) Vulnerability

fonttools XML External Entity Injection (XXE) Vulnerability

▾ Twilightfonttools · fonttoolsEPSS 1.2%via OSV

Most-affected vendors

By CVEs published in the period.