VulnSea

Weekly digest

Week 6, 2024 (5–11 Feb)

21 new CVEs this week, in line with the recent average. Severity skewed high: 6 critical and 8 high, 67% of the total. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. clearml was the most-affected vendor with 3.

21
New CVEs
6
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2024-21762Critical· 9.8CISA KEV0dayPoC
2y ago

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

▾ Hadalfortinet · fortiproxyEPSS 83%via NVD
CVE-2024-24590High· 8.8PoC
2y ago

Allegro AI ClearML vulnerable to deserialization of untrusted data

Allegro AI ClearML vulnerable to deserialization of untrusted data

▾ Midnightclearml · clearmlEPSS 2.5%via OSV
CVE-2024-21490High· 7.5PoC
2y ago

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. Wit…

▾ Midnightangularjs · angular.jsEPSS 1.9%via NVD
CVE-2024-25675Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.184

An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.

▾ Midnightmisp-project · mispEPSS 0.82%via NVD
CVE-2024-25674Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.184

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

▾ Midnightmisp-project · mispEPSS 0.78%via NVD
CVE-2024-24811Critical· 9.8
2y ago

SQLAlchemyDA unauthenticated arbitrary SQL query execution

SQLAlchemyDA unauthenticated arbitrary SQL query execution

▾ Midnightproducts-sqlalchemyda · products-sqlalchemydaEPSS 0.89%via OSV
CVE-2024-24563Critical· 9.8
2y ago

Vyper negative array index bounds checks

Vyper negative array index bounds checks

▾ Midnightvyper · vyperEPSS 1.5%via OSV
CVE-2024-24825Critical· 9.1
2y ago

DIRAC's TokenManager does not check permissions on cached tokens

DIRAC's TokenManager does not check permissions on cached tokens

▾ Midnightdirac · diracEPSS 0.53%via OSV
CVE-2024-24591High· 8.8
2y ago

Allegro AI ClearML path traversal vulnerability

Allegro AI ClearML path traversal vulnerability

▾ Twilightclearml · clearmlEPSS 0.80%via OSV
CVE-2024-1314High· 8.6
2y ago

Kinto Attachment's attachments can be replaced on read-only records

Kinto Attachment's attachments can be replaced on read-only records

▾ Twilightkinto-attachment · kinto-attachmentvia OSV
CVE-2023-32192High· 8.3
2y ago

Rancher API Server Cross-site Scripting Vulnerability

Rancher API Server Cross-site Scripting Vulnerability

▾ Twilightrancher · github.com/rancher/apiserverEPSS 0.37%via OSV
CVE-2024-24680High· 7.5
2y ago

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

▾ Twilightdjangoproject · djangoEPSS 1.6%via NVD

Most-affected vendors

By CVEs published in the period.