VulnSea

Weekly digest

Week 16, 2024 (15–21 Apr)

31 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 16 high, 55% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mlflow was the most-affected vendor with 5.

31
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 31 published.

CVE-2024-1561High· 7.5PoC
2y ago

gradio vulnerable to Path Traversal

gradio vulnerable to Path Traversal

▾ Midnightgradio · gradioEPSS 9.3%via OSV
CVE-2024-1483High· 7.5PoC
2y ago

mlflow Path Traversal vulnerability

mlflow Path Traversal vulnerability

▾ Midnightmlflow · mlflowEPSS 2.7%via OSV
CVE-2024-28056Critical· 9.8
2y ago

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "…

▾ Midnightamazon · aws_amplify_cliEPSS 1.7%via NVD
CVE-2024-26822High· 8.7
2y ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: set correct id, uid and cruid for multiuser automounts When uid, gid and cruid are not specified, we need to dynamically set them into the filesystem cont…

In the Linux kernel, the following vulnerability has been resolved: smb: client: set correct id, uid and cruid for multiuser automounts When uid, gid and cruid are not specified, we need to dynamically set them into the filesystem cont…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-1183Medium· 6.5PoC
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

▾ Twilightgradio · gradioEPSS 1.8%via OSV
CVE-2024-1135High· 8.2
2y ago

Request smuggling leading to endpoint restriction bypass in Gunicorn

Request smuggling leading to endpoint restriction bypass in Gunicorn

▾ Twilightgunicorn · gunicornEPSS 3.0%via OSV
CVE-2024-1132High· 8.1
2y ago

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information withi…

▾ Twilightredhat · build_of_keycloakEPSS 1.6%via NVD
CVE-2024-1560High· 8.1
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.86%via OSV
CVE-2024-26823High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Restore quirk probing for ACPI-based systems While refactoring the way the ITSs are probed, the handling of quirks applicable to ACPI-based platfor…

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Restore quirk probing for ACPI-based systems While refactoring the way the ITSs are probed, the handling of quirks applicable to ACPI-based platfor…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-4340High· 7.5
2y ago

sqlparse parsing heavily nested list leads to Denial of Service

sqlparse parsing heavily nested list leads to Denial of Service

▾ Twilightsqlparse · sqlparseEPSS 3.2%via OSV
CVE-2024-31580High· 7.5
2y ago

PyTorch heap buffer overflow vulnerability

PyTorch heap buffer overflow vulnerability

▾ Twilighttorch · torchEPSS 0.22%via OSV
CVE-2024-1249High· 7.4
2y ago

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…

▾ TwilightRed Hat · keycloakEPSS 0.44%via NVD

Most-affected vendors

By CVEs published in the period.