Weekly digest
Week 7, 2024 (12–18 Feb)
A quiet week: only 10 new CVEs against a recent average of about 20. Severity skewed high: 7 high, 70% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2024-21338High· 7.8CISA KEV0dayPoCWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-1488High· 8.0A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the…
CVE-2024-1485High· 8.0registry-support: decompress can delete files outside scope via relative paths
registry-support: decompress can delete files outside scope via relative paths
CVE-2024-24762High· 7.5python-multipart vulnerable to Content-Type Header ReDoS
python-multipart vulnerable to Content-Type Header ReDoS
CVE-2024-3572High· 7.5Scrapy decompression bomb vulnerability
Scrapy decompression bomb vulnerability
CVE-2024-3574High· 7.5Scrapy authorization header leakage on cross-domain redirect
Scrapy authorization header leakage on cross-domain redirect
CVE-2023-6123High· 7.5Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.
Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.
CVE-2023-20579Medium· 6.0Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.
CVE-2023-6152Medium· 5.4Email Validation Bypass And Preventing Sign Up From Email's Owner
Email Validation Bypass And Preventing Sign Up From Email's Owner
CVE-2024-1459Medium· 5.3A path traversal vulnerability was found in Undertow
A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or res…
Most-affected vendors
By CVEs published in the period.