VulnSea

Weekly digest

Week 3, 2024 (15–21 Jan)

A heavy week: 28 new CVEs, well above the recent average of about 16. Severity skewed high: 5 critical and 13 high, 64% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 3.

28
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 28 published.

CVE-2023-27168Critical· 9.8PoC
2y ago

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

▾ Abyssalxpand-it · write-back_managerEPSS 1.3%via NVD
CVE-2024-22416Critical· 9.6PoC
2y ago

Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

▾ Abyssalpyload-ng · pyload-ngEPSS 0.95%via OSV
CVE-2024-23679Critical· 9.8
2y ago

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.

▾ Midnightenonic · xpEPSS 0.84%via NVD
CVE-2024-0521Critical· 9.3
2y ago

Code Injection in paddlepaddle

Code Injection in paddlepaddle

▾ Midnightpaddlepaddle · paddlepaddleEPSS 0.46%via OSV
CVE-2024-23687Critical· 9.1
2y ago

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…

▾ Midnightopenlibraryfoundation · mod-data-export-springEPSS 0.65%via NVD
CVE-2024-23689High· 8.8
2y ago

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…

▾ Twilightclickhouse · java_librariesEPSS 0.68%via NVD
CVE-2024-22424High· 8.3
2y ago

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

▾ Twilightargoproj · github.com/argoproj/argo-cdEPSS 0.48%via OSV
CVE-2024-23683High· 8.2
2y ago

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim execu…

▾ Twilightls1intum · artemis_java_test_sandboxEPSS 0.36%via NVD
CVE-2024-23682High· 8.2
2y ago

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the…

▾ Twilightls1intum · artemis_java_test_sandboxEPSS 0.35%via NVD
CVE-2024-23681High· 8.2
2y ago

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a vic…

▾ Twilightls1intum · artemis_java_test_sandboxEPSS 0.34%via NVD
CVE-2023-50447High· 8.1
2y ago

Arbitrary Code Execution in Pillow

Arbitrary Code Execution in Pillow

▾ Twilightpillow · pillowEPSS 1.7%via OSV
CVE-2024-22421High· 7.6
2y ago

JupyterLab vulnerable to potential authentication and CSRF tokens leak

JupyterLab vulnerable to potential authentication and CSRF tokens leak

▾ Twilightjupyterlab · jupyterlabEPSS 0.67%via OSV

Most-affected vendors

By CVEs published in the period.