Weekly digest
Week 20, 2024 (13–19 May)
18 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 7 high, 56% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mranderson was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2024-34359Critical· 9.6llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
CVE-2024-4078Critical· 9.8LoLLMS Command Injection vulnerability
LoLLMS Command Injection vulnerability
CVE-2021-41244Critical· 9.1Grafana Fine-grained access control vulnerability
Grafana Fine-grained access control vulnerability
CVE-2024-4181High· 8.8RunGptLLM class in LlamaIndex has a command injection
RunGptLLM class in LlamaIndex has a command injection
CVE-2024-35887High· 8.8ax25: fix use-after-free bugs caused by ax25_ds_del_timer
In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_…
CVE-2024-3727High· 8.3A flaw was found in the github.com/containers/image library
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVE-2023-45745High· 7.9Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2023-52676High· 7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current …
In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current …
CVE-2024-34707High· 7.5Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
CVE-2024-4264High· 7.2litellm passes untrusted data to `eval` function without sanitization
litellm passes untrusted data to `eval` function without sanitization
CVE-2024-3822Medium· 4.8PoCThe Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…
CVE-2024-5042Medium· 6.6A flaw was found in the Submariner project
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromis…
Most-affected vendors
By CVEs published in the period.