VulnSea

Weekly digest

Week 20, 2024 (13–19 May)

18 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 7 high, 56% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mranderson was the most-affected vendor with 3.

18
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2024-34359Critical· 9.6
2y ago

llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata

llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata

▾ Midnightllama-cpp-python · llama-cpp-pythonEPSS 26%via OSV
CVE-2024-4078Critical· 9.8
2y ago

LoLLMS Command Injection vulnerability

LoLLMS Command Injection vulnerability

▾ Midnightlollms · lollmsEPSS 0.92%via OSV
CVE-2021-41244Critical· 9.1
2y ago

Grafana Fine-grained access control vulnerability

Grafana Fine-grained access control vulnerability

▾ Midnightgrafana · github.com/grafana/grafanaEPSS 2.9%via OSV
CVE-2024-4181High· 8.8
2y ago

RunGptLLM class in LlamaIndex has a command injection

RunGptLLM class in LlamaIndex has a command injection

▾ Twilightllama-index · llama-indexEPSS 2.1%via OSV
CVE-2024-35887High· 8.8
2y ago

ax25: fix use-after-free bugs caused by ax25_ds_del_timer

In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_…

▾ TwilightLinux · LinuxEPSS 0.34%via CVEORG
CVE-2024-3727High· 8.3
2y ago

A flaw was found in the github.com/containers/image library

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

▾ Twilightcontainers · github.com/containers/imageEPSS 1.3%via NVD
CVE-2023-45745High· 7.9
2y ago

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

▾ Twilightintel · tdx_moduleEPSS 0.38%via NVD
CVE-2023-52676High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current …

In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current …

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-34707High· 7.5
2y ago

Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

▾ Twilightnautobot · nautobotEPSS 0.61%via OSV
CVE-2024-4264High· 7.2
2y ago

litellm passes untrusted data to `eval` function without sanitization

litellm passes untrusted data to `eval` function without sanitization

▾ Twilightlitellm · litellmEPSS 0.88%via OSV
CVE-2024-3822Medium· 4.8PoC
2y ago

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…

▾ Twilightmranderson · base64_encoder/decoderEPSS 0.75%via NVD
CVE-2024-5042Medium· 6.6
2y ago

A flaw was found in the Submariner project

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromis…

▾ SunlitRed Hat · submariner-operatorEPSS 0.51%via NVD

Most-affected vendors

By CVEs published in the period.