VulnSea

Weekly digest

Week 13, 2024 (25–31 Mar)

A quiet week: only 14 new CVEs against a recent average of about 37. Of those, 6 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

14
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2024-1023Medium· 6.5PoC
2y ago

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. …

▾ TwilightRed Hat · vertx-coreEPSS 1.7%via NVD
CVE-2024-20271High· 8.6
2y ago

Cisco Access Point Software Denial of Service Vulnerability (CVE-2024-20271)

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficien…

▾ TwilightCisco · Cisco Aironet Access Point SoftwareEPSS 0.63%via CSAF
CVE-2024-28233High· 8.1
2y ago

Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing

Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing

▾ Twilightjupyterhub · jupyterhubEPSS 0.33%via OSV
CVE-2024-26646High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer and provides its location to the hardware, which uses it to update t…

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer and provides its location to the hardware, which uses it to update t…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-29640High
2y ago

aliyundrive-webdav vulnerable to Command Injection

aliyundrive-webdav vulnerable to Command Injection

▾ Twilightaliyundrive-webdav · aliyundrive-webdavEPSS 1.2%via OSV
CVE-2024-29189High· 7.4
2y ago

ansys-geometry-core OS Command Injection vulnerability

ansys-geometry-core OS Command Injection vulnerability

▾ Twilightansys-geometry-core · ansys-geometry-coreEPSS 0.34%via OSV
CVE-2024-2206High· 7.3
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

▾ Twilightgradio · gradioEPSS 0.42%via OSV
CVE-2024-29893Medium· 6.5
2y ago

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.97%via OSV
CVE-2024-1313Medium· 6.5
2y ago

grafana: vulnerable to authorization bypass (CVE-2024-1313)

A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2024-1455Medium· 5.9
2y ago

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

▾ Sunlitlangchain-core · langchain-coreEPSS 0.76%via OSV
CVE-2024-20265Medium· 5.9
2y ago

Cisco Access Point Software Secure Boot Bypass Vulnerability (CVE-2024-20265)

A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.25%via CSAF
CVE-2024-29735Medium· 5.3
2y ago

Apache Airflow Improper Preservation of Permissions vulnerability

Apache Airflow Improper Preservation of Permissions vulnerability

▾ Sunlitapache-airflow · apache-airflowEPSS 1.5%via OSV

Most-affected vendors

By CVEs published in the period.