VulnSea

Weekly digest

Week 7, 2024 (12–18 Feb)

A quiet week: only 10 new CVEs against a recent average of about 20. Severity skewed high: 7 high, 70% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

10
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2024-21338High· 7.8CISA KEV0dayPoC
2y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 60%via NVD
CVE-2024-1488High· 8.0
2y ago

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the…

▾ Twilightfedoraproject · unboundEPSS 0.32%via NVD
CVE-2024-1485High· 8.0
2y ago

registry-support: decompress can delete files outside scope via relative paths

registry-support: decompress can delete files outside scope via relative paths

▾ Twilightdevfile · github.com/devfile/registry-support/registry-libraryEPSS 0.94%via OSV
CVE-2024-24762High· 7.5
2y ago

python-multipart vulnerable to Content-Type Header ReDoS

python-multipart vulnerable to Content-Type Header ReDoS

▾ Twilightpython-multipart · python-multipartEPSS 1.5%via OSV
CVE-2024-3572High· 7.5
2y ago

Scrapy decompression bomb vulnerability

Scrapy decompression bomb vulnerability

▾ Twilightscrapy · scrapyEPSS 0.81%via OSV
CVE-2024-3574High· 7.5
2y ago

Scrapy authorization header leakage on cross-domain redirect

Scrapy authorization header leakage on cross-domain redirect

▾ Twilightscrapy · scrapyEPSS 0.65%via OSV
CVE-2023-6123High· 7.5
2y ago

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

▾ Twilightopentext · alm_octaneEPSS 0.51%via NVD
CVE-2023-20579Medium· 6.0
2y ago

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

▾ Sunlitamd · ryzen_7_5700g_firmwareEPSS 0.16%via NVD
CVE-2023-6152Medium· 5.4
2y ago

Email Validation Bypass And Preventing Sign Up From Email's Owner

Email Validation Bypass And Preventing Sign Up From Email's Owner

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.4%via OSV
CVE-2024-1459Medium· 5.3
2y ago

A path traversal vulnerability was found in Undertow

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or res…

▾ Sunlitredhat · undertowEPSS 1.7%via NVD

Most-affected vendors

By CVEs published in the period.