VulnSea

Weekly digest

Week 18, 2024 (29 Apr – 5 May)

33 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 16 high, 55% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. ryu was the most-affected vendor with 6.

33
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 33 published.

CVE-2023-50224Medium· 6.5CISA KEV0day
2y ago

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Au…

▾ Midnighttp-link · tl-wr841n_firmwareEPSS 16%via NVD
CVE-2024-33775High· 8.8PoC
2y ago

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

▾ Midnightnagios · nagios_xiEPSS 1.4%via NVD
CVE-2024-26305Critical· 9.8
2y ago

There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP p…

There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP p…

▾ Midnightarubanetworks · sd-wanEPSS 15%via NVD
CVE-2024-31823Critical· 9.8
2y ago

An issue in Ecommerce-CodeIgniter-Bootstrap commit v

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.

▾ Midnightecommerce-codeigniter-bootstrap_project · ecommerce-codeigniter-bootstrapEPSS 1.7%via NVD
CVE-2023-46960High· 8.6
2y ago

PyPXE Buffer Overflow vulnerability

PyPXE Buffer Overflow vulnerability

▾ Twilightpypxe · pypxeEPSS 0.54%via OSV
CVE-2024-34073High· 7.8
2y ago

sagemaker-python-sdk Command Injection vulnerability

sagemaker-python-sdk Command Injection vulnerability

▾ Twilightsagemaker · sagemakerEPSS 1.2%via OSV
CVE-2024-34072High· 7.8
2y ago

sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data

sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data

▾ Twilightsagemaker · sagemakerEPSS 0.41%via OSV
CVE-2022-48670High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to …

In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to …

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2024-34489High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.68%via OSV
CVE-2024-34488High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.68%via OSV
CVE-2024-34486High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.65%via OSV
CVE-2024-34483High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.68%via OSV

Most-affected vendors

By CVEs published in the period.