VulnSea

Weekly digest

Week 11, 2024 (11–17 Mar)

28 new CVEs this week, in line with the recent average. Severity skewed high: 5 critical and 12 high, 61% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 9.

28
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 28 published.

CVE-2024-27102Critical· 9.9PoC
2y ago

Wings is the server control plane for Pterodactyl Panel

Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full sco…

▾ Abyssalpterodactyl · wingsEPSS 0.55%via NVD
CVE-2023-42789Critical· 9.8PoC
2y ago

A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 throug…

A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 throug…

▾ Abyssalfortinet · fortiproxyEPSS 3.3%via NVD
CVE-2024-28423Critical· 9.8
2y ago

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vuln…

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

▾ Midnightairflow-diagrams · airflow-diagramsEPSS 0.78%via OSV
CVE-2024-28175Critical· 9.0
2y ago

Cross-site scripting on application summary component

Cross-site scripting on application summary component

▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.65%via OSV
CVE-2024-21400Critical· 9.0
2y ago

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · confcomEPSS 2.2%via NVD
CVE-2024-26164High· 8.8
2y ago

Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server

Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server

▾ Twilightmssql-django · mssql-djangoEPSS 2.1%via OSV
CVE-2023-42790High· 8.1
2y ago

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.…

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.…

▾ Twilightfortinet · fortiproxyEPSS 1.1%via NVD
CVE-2024-26620High· 8.2⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The vfio_ap_mdev_filter_matrix function is called whenever a new adapter or domain is assigned to the mdev

In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The vfio_ap_mdev_filter_matrix function is called whenever a new adapter or domain is assigned to the mdev. The purpose of…

▾ Twilightlinux · linux_kernelEPSS 0.63%via NVD
CVE-2024-26617High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: move mmu notification mechanism inside mm lock Move mmu notification mechanism inside mm lock to prevent race condition in other components which dep…

In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: move mmu notification mechanism inside mm lock Move mmu notification mechanism inside mm lock to prevent race condition in other components which dep…

▾ Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2024-26614High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program locally, it causes the following issue: pvqspinlock: lock 0xffff9d181cd5c…

In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program locally, it causes the following issue: pvqspinlock: lock 0xffff9d181cd5c…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2024-26610High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix a memory corruption iwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means that if we copy to iwl_fw_ini_trigger_tlv::data + offset whil…

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix a memory corruption iwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means that if we copy to iwl_fw_ini_trigger_tlv::data + offset whil…

▾ Twilightlinux · linux_kernelEPSS 0.31%via NVD
CVE-2023-52494High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Add alignment check for event ring read pointer Though we do check the event ring read pointer by "is_valid_ring_ptr" to make sure it is in the buffer …

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Add alignment check for event ring read pointer Though we do check the event ring read pointer by "is_valid_ring_ptr" to make sure it is in the buffer …

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD

Most-affected vendors

By CVEs published in the period.