Weekly digest
Week 18, 2024 (29 Apr – 5 May)
33 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 16 high, 55% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. ryu was the most-affected vendor with 6.
New this week, ranked by depth score
The 12 that matter most of the 33 published.
CVE-2023-50224Medium· 6.5CISA KEV0dayTP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Au…
CVE-2024-33775High· 8.8PoCAn issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
CVE-2024-26305Critical· 9.8There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP p…
There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP p…
CVE-2024-31823Critical· 9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
CVE-2023-46960High· 8.6PyPXE Buffer Overflow vulnerability
PyPXE Buffer Overflow vulnerability
CVE-2024-34073High· 7.8sagemaker-python-sdk Command Injection vulnerability
sagemaker-python-sdk Command Injection vulnerability
CVE-2024-34072High· 7.8sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
CVE-2022-48670High· 7.8In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to …
In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to …
CVE-2024-34489High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34488High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34486High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34483High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
Most-affected vendors
By CVEs published in the period.