Weekly digest
Week 19, 2024 (6–12 May)
A quiet week: only 8 new CVEs against a recent average of about 30. Severity skewed high: 1 critical and 3 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2024-34069High· 7.5PoCWerkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2024-32874Critical· 9.3Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
CVE-2024-32982High· 8.2Litestar and Starlite vulnerable to Path Traversal
Litestar and Starlite vulnerable to Path Traversal
CVE-2024-34064Medium· 5.4PoCJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-34078HighArbitrary HTML present after sanitization because of unicode normalization
Arbitrary HTML present after sanitization because of unicode normalization
CVE-2024-34517Medium· 6.5The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
CVE-2024-32886Medium· 4.9Vitess vulnerable to infinite memory consumption and vtgate crash
Vitess vulnerable to infinite memory consumption and vtgate crash
CVE-2024-28148Medium· 4.3Apache Superset Incorrect Authorization vulnerability
Apache Superset Incorrect Authorization vulnerability
Most-affected vendors
By CVEs published in the period.