VulnSea

Weekly digest

Week 5, 2024 (29 Jan – 4 Feb)

A heavy week: 32 new CVEs, well above the recent average of about 18. Of those, 4 critical and 8 high. 8 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. moby was the most-affected vendor with 5.

32
New CVEs
4
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 32 published.

CVE-2024-21893High· 8.2CISA KEV0dayPoC
2y ago

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2021-43798High· 7.5CISA KEVPoC
2y ago

Grafana path traversal

Grafana path traversal

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 89%via OSV
CVE-2024-1086High· 7.8CISA KEVPoC
2y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

▾ Abyssalnetapp · h300s_firmwareEPSS 28%via NVD
CVE-2024-23652Critical· 10.0PoC
2y ago

BuildKit vulnerable to possible host system access from mount stub cleaner

BuildKit vulnerable to possible host system access from mount stub cleaner

▾ Abyssalmoby · github.com/moby/buildkitEPSS 2.1%via OSV
CVE-2024-21626High· 8.6PoC
2y ago

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc…

▾ Midnightlinuxfoundation · runcEPSS 18%via NVD
CVE-2024-23334Medium· 5.9PoC
2y ago

aiohttp is vulnerable to directory traversal

aiohttp is vulnerable to directory traversal

▾ Twilightaiohttp · aiohttpEPSS 77%via OSV
CVE-2024-22902Critical· 9.8
2y ago

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

▾ Midnightvinchin · vinchin_backup_and_recoveryEPSS 1.1%via NVD
CVE-2024-24561Critical· 9.8
2y ago

Vyper's bounds check on built-in `slice()` function can be overflowed

Vyper's bounds check on built-in `slice()` function can be overflowed

▾ Midnightvyper · vyperEPSS 0.90%via OSV
CVE-2024-1015Critical· 9.8
2y ago

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of th…

▾ Midnightse-elektronic · e-ddc3.3_firmwareEPSS 1.8%via NVD
CVE-2024-21649High· 8.8
2y ago

vantage6 remote code execution vulnerability

vantage6 remote code execution vulnerability

▾ Twilightvantage6 · vantage6EPSS 1.3%via OSV
CVE-2024-21485Medium· 6.5PoC
2y ago

Dash apps vulnerable to Cross-site Scripting

Dash apps vulnerable to Cross-site Scripting

▾ Twilightdash-core-components · dash-core-componentsEPSS 1.5%via OSV
CVE-2021-41091Medium· 5.9PoC
2y ago

Moby (Docker Engine) Insufficiently restricted permissions on data directory

Moby (Docker Engine) Insufficiently restricted permissions on data directory

▾ Twilightmoby · github.com/moby/mobyEPSS 2.8%via OSV

Most-affected vendors

By CVEs published in the period.