Weekly digest
Week 13, 2024 (25–31 Mar)
A quiet week: only 14 new CVEs against a recent average of about 37. Of those, 6 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2024-1023Medium· 6.5PoCA vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. …
CVE-2024-20271High· 8.6Cisco Access Point Software Denial of Service Vulnerability (CVE-2024-20271)
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficien…
CVE-2024-28233High· 8.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
CVE-2024-26646High· 7.8In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer and provides its location to the hardware, which uses it to update t…
In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer and provides its location to the hardware, which uses it to update t…
CVE-2024-29640Highaliyundrive-webdav vulnerable to Command Injection
aliyundrive-webdav vulnerable to Command Injection
CVE-2024-29189High· 7.4ansys-geometry-core OS Command Injection vulnerability
ansys-geometry-core OS Command Injection vulnerability
CVE-2024-2206High· 7.3gradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-1313Medium· 6.5grafana: vulnerable to authorization bypass (CVE-2024-1313)
A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…
CVE-2024-1455Medium· 5.9LangChain's XMLOutputParser vulnerable to XML Entity Expansion
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-20265Medium· 5.9Cisco Access Point Software Secure Boot Bypass Vulnerability (CVE-2024-20265)
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…
CVE-2024-29735Medium· 5.3Apache Airflow Improper Preservation of Permissions vulnerability
Apache Airflow Improper Preservation of Permissions vulnerability
Most-affected vendors
By CVEs published in the period.