VulnSea

Weekly digest

Week 19, 2024 (6–12 May)

A quiet week: only 8 new CVEs against a recent average of about 30. Severity skewed high: 1 critical and 3 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

8
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2024-34069High· 7.5PoC
2y ago

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

▾ Midnightwerkzeug · werkzeugEPSS 3.4%via OSV
CVE-2024-32874Critical· 9.3
2y ago

Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service

Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service

▾ Midnightfrigate · frigateEPSS 0.77%via OSV
CVE-2024-32982High· 8.2
2y ago

Litestar and Starlite vulnerable to Path Traversal

Litestar and Starlite vulnerable to Path Traversal

▾ Twilightlitestar · litestarEPSS 0.72%via OSV
CVE-2024-34064Medium· 5.4PoC
2y ago

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

▾ Twilightjinja2 · jinja2EPSS 0.98%via OSV
CVE-2024-34078High
2y ago

Arbitrary HTML present after sanitization because of unicode normalization

Arbitrary HTML present after sanitization because of unicode normalization

▾ Twilighthtml-sanitizer · html-sanitizerEPSS 0.55%via OSV
CVE-2024-34517Medium· 6.5
2y ago

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

▾ Sunlitneo4j · neo4jEPSS 0.63%via NVD
CVE-2024-32886Medium· 4.9
2y ago

Vitess vulnerable to infinite memory consumption and vtgate crash

Vitess vulnerable to infinite memory consumption and vtgate crash

▾ Sunlitvitessio · github.com/vitessio/vitessEPSS 0.75%via OSV
CVE-2024-28148Medium· 4.3
2y ago

Apache Superset Incorrect Authorization vulnerability

Apache Superset Incorrect Authorization vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.70%via OSV

Most-affected vendors

By CVEs published in the period.