Weekly digest
Week 5, 2024 (29 Jan – 4 Feb)
A heavy week: 32 new CVEs, well above the recent average of about 18. Of those, 4 critical and 8 high. 8 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. moby was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 32 published.
CVE-2024-21893High· 8.2CISA KEV0dayPoCA server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…
CVE-2021-43798High· 7.5CISA KEVPoCGrafana path traversal
Grafana path traversal
CVE-2024-1086High· 7.8CISA KEVPoCA use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
CVE-2024-23652Critical· 10.0PoCBuildKit vulnerable to possible host system access from mount stub cleaner
BuildKit vulnerable to possible host system access from mount stub cleaner
CVE-2024-21626High· 8.6PoCrunc is a CLI tool for spawning and running containers on Linux according to the OCI specification
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc…
CVE-2024-23334Medium· 5.9PoCaiohttp is vulnerable to directory traversal
aiohttp is vulnerable to directory traversal
CVE-2024-22902Critical· 9.8Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
CVE-2024-24561Critical· 9.8Vyper's bounds check on built-in `slice()` function can be overflowed
Vyper's bounds check on built-in `slice()` function can be overflowed
CVE-2024-1015Critical· 9.8Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of th…
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
vantage6 remote code execution vulnerability
CVE-2024-21485Medium· 6.5PoCDash apps vulnerable to Cross-site Scripting
Dash apps vulnerable to Cross-site Scripting
CVE-2021-41091Medium· 5.9PoCMoby (Docker Engine) Insufficiently restricted permissions on data directory
Moby (Docker Engine) Insufficiently restricted permissions on data directory
Most-affected vendors
By CVEs published in the period.