VulnSea

Weekly digest

Week 17, 2024 (22–28 Apr)

23 new CVEs this week, in line with the recent average. Of those, 2 critical and 8 high. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. rancher was the most-affected vendor with 3.

23
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 23 published.

CVE-2024-33668Critical· 9.1PoC
2y ago

An issue was discovered in Zammad before 6.3.0

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no …

▾ Abyssalzammad · zammadEPSS 0.45%via NVD
CVE-2020-8559Medium· 6.8PoC
2y ago

Privilege Escalation in Kubernetes

Privilege Escalation in Kubernetes

▾ Twilightapimachinery · k8s.io/apimachineryEPSS 6.1%via OSV
CVE-2024-32880Critical· 9.1
2y ago

pyLoad allows upload to arbitrary folder lead to RCE

pyLoad allows upload to arbitrary folder lead to RCE

▾ Midnightpyload-ng · pyload-ngEPSS 1.4%via OSV
CVE-2021-31999High· 8.8
2y ago

Rancher Privilege escalation vulnerability via malicious "Connection" header

Rancher Privilege escalation vulnerability via malicious "Connection" header

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2021-25318High· 8.8
2y ago

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2024-22373High· 8.1
2y ago

An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23

An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide…

▾ Twilightmalaterre · grassroots_dicomEPSS 1.7%via NVD
CVE-2021-36775High· 8.0
2y ago

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.97%via OSV
CVE-2024-1139High· 7.7
2y ago

A credentials leak vulnerability was found in the cluster monitoring operator in OCP

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

▾ TwilightEPSS 0.89%via NVD
CVE-2024-28717High· 7.8
2y ago

OpenStack Storlets arbitrary code execution vulnerability

OpenStack Storlets arbitrary code execution vulnerability

▾ Twilightstorlets · storletsEPSS 0.89%via OSV
CVE-2024-33663High· 7.4
2y ago

python-jose algorithm confusion with OpenSSH ECDSA keys

python-jose algorithm confusion with OpenSSH ECDSA keys

▾ Twilightpython-jose · python-joseEPSS 0.31%via OSV
CVE-2024-3154High· 7.2
2y ago

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.4%via NVD
CVE-2024-32868Medium· 6.5
2y ago

ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email

ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount…

▾ Sunlitzitadel · zitadelEPSS 0.46%via NVD

Most-affected vendors

By CVEs published in the period.