Weekly digest
Week 15, 2024 (8–14 Apr)
23 new CVEs this week, in line with the recent average. Severity skewed high: 4 critical and 10 high, 61% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 23 published.
CVE-2024-2952Critical· 9.8LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
CVE-2024-2195Critical· 9.8Aim Web API vulnerable to Remote Code Execution
Aim Web API vulnerable to Remote Code Execution
CVE-2024-26811Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server. ksmbd should val…
CVE-2024-32644Critical· 9.1Evmos transaction execution not accounting for all state transition after interaction with precompiles
Evmos transaction execution not accounting for all state transition after interaction with precompiles
CVE-2024-2196High· 8.8Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability
Ollama DNS rebinding vulnerability
CVE-2024-3651Medium· 6.2PoCInternationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
CVE-2024-22423High· 8.3yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
CVE-2023-52070High· 8.4JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method
JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine…
CVE-2024-32005High· 8.2NiceGUI allows potential access to local file system
NiceGUI allows potential access to local file system
CVE-2024-29905High· 8.1DIRAC: Unauthorized users can read proxy contents during generation
DIRAC: Unauthorized users can read proxy contents during generation
CVE-2024-26815High· 7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: proper TCA_TAPRIO_TC_ENTRY_INDEX check taprio_parse_tc_entry() is not correctly checking TCA_TAPRIO_TC_ENTRY_INDEX attribute: int tc; // Signed va…
In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: proper TCA_TAPRIO_TC_ENTRY_INDEX check taprio_parse_tc_entry() is not correctly checking TCA_TAPRIO_TC_ENTRY_INDEX attribute: int tc; // Signed va…
Most-affected vendors
By CVEs published in the period.