VulnSea

Weekly digest

Week 9, 2024 (26 Feb – 3 Mar)

A heavy week: 104 new CVEs, well above the recent average of about 23. Severity skewed high: 9 critical and 71 high, 77% of the total. 5 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 77.

104
New CVEs
9
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 104 published.

CVE-2024-27292High· 7.5PoC
2y ago

Docassemble unauthorized access through URL manipulation

Docassemble unauthorized access through URL manipulation

▾ Midnightdocassemble-webapp · docassemble-webappEPSS 69%via OSV
CVE-2024-25723Medium· 6.5PoC
2y ago

ZenML Server Remote Privilege Escalation Vulnerability

ZenML Server Remote Privilege Escalation Vulnerability

▾ Twilightzenml · zenmlEPSS 71%via OSV
CVE-2024-23052Critical· 9.8
2y ago

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

▾ Midnight5kcrm · wukong_crmEPSS 4.9%via NVD
CVE-2019-25162High· 7.8PoC
2y ago

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after f…

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after f…

▾ Midnightlinux · linux_kernelEPSS 0.38%via NVD
CVE-2023-52515Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following ac…

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following ac…

▾ Midnightlinux · linux_kernelEPSS 0.61%via NVD
CVE-2023-52480Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix race condition between session lookup and expire Thread A + Thread B ksmbd_session_lookup | smb2_sess_setup sess = …

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix race condition between session lookup and expire Thread A + Thread B ksmbd_session_lookup | smb2_sess_setup sess = …

▾ Midnightlinux · linux_kernelEPSS 0.48%via NVD
CVE-2021-47036Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: udp: skip L4 aggregation for UDP tunnel packets If NETIF_F_GRO_FRAGLIST or NETIF_F_GRO_UDP_FWD are enabled, and there are UDP tunnels available in the system, udp_gro_…

In the Linux kernel, the following vulnerability has been resolved: udp: skip L4 aggregation for UDP tunnel packets If NETIF_F_GRO_FRAGLIST or NETIF_F_GRO_UDP_FWD are enabled, and there are UDP tunnels available in the system, udp_gro_…

▾ Midnightlinux · linux_kernelEPSS 0.53%via NVD
CVE-2021-47013Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If some error happens in emac_tx_fill_tp…

In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If some error happens in emac_tx_fill_tp…

▾ Midnightlinux · linux_kernelEPSS 0.78%via NVD
CVE-2021-46999Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few of envs, the call trace is as below: [] general protection fault, ..

In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few of envs, the call trace is as below: [] general protection fault, ... 0x29…

▾ Midnightlinux · linux_kernelEPSS 0.74%via NVD
CVE-2021-46911Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ch_ktls: Fix kernel panic Taking page refcount is not ideal and causes kernel panic sometimes

In the Linux kernel, the following vulnerability has been resolved: ch_ktls: Fix kernel panic Taking page refcount is not ideal and causes kernel panic sometimes. It's better to take tx_ctx lock for the complete skb transmit, to avoid …

▾ Midnightlinux · linux_kernelEPSS 0.59%via NVD
CVE-2024-25128Critical· 9.1
2y ago

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

▾ Midnightflask-appbuilder · flask-appbuilderEPSS 0.86%via OSV
CVE-2019-25160Critical· 9.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk()

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Bot…

▾ Midnightlinux · linux_kernelEPSS 0.74%via NVD

Most-affected vendors

By CVEs published in the period.