VulnSea

Weekly digest

Week 21, 2024 (20–26 May)

23 new CVEs this week, in line with the recent average. Of those, 3 critical and 4 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 6.

23
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 23 published.

CVE-2024-36039Critical· 9.8PoC
2y ago

PyMySQL SQL Injection vulnerability

PyMySQL SQL Injection vulnerability

▾ Abyssalpymysql · pymysqlEPSS 0.69%via OSV
CVE-2024-35059Critical· 9.8
2y ago

NASA AIT-Core vulnerable to remote code execution

NASA AIT-Core vulnerable to remote code execution

▾ Midnightait-core · ait-coreEPSS 0.45%via OSV
CVE-2024-35056Critical· 9.8
2y ago

NASA AIT-Core vulnerable to SQL Injection

NASA AIT-Core vulnerable to SQL Injection

▾ Midnightait-core · ait-coreEPSS 0.61%via OSV
CVE-2024-35058High· 7.5
2y ago

NASA AIT-Core vulnerable to remote code execution

NASA AIT-Core vulnerable to remote code execution

▾ Twilightait-core · ait-coreEPSS 0.44%via OSV
CVE-2024-35057High· 7.5
2y ago

NASA AIT-Core vulnerable to remote code execution

NASA AIT-Core vulnerable to remote code execution

▾ Twilightait-core · ait-coreEPSS 0.44%via OSV
CVE-2024-35061High· 7.3
2y ago

NASA AIT-Core uses unencrypted channels to exchange data over the network

NASA AIT-Core uses unencrypted channels to exchange data over the network

▾ Twilightait-core · ait-coreEPSS 0.55%via OSV
CVE-2021-47354High· 7.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.

▾ Twilightlinux · linux_kernelEPSS 0.73%via NVD
CVE-2024-36013Medium· 6.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type vo…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type vo…

▾ Sunlitlinux · linux_kernelEPSS 0.48%via NVD
CVE-2024-35180Medium· 6.1
2y ago

OMERO.web must check that the JSONP callback is a valid function

OMERO.web must check that the JSONP callback is a valid function

▾ Sunlitomero-web · omero-webEPSS 0.29%via OSV
CVE-2024-35195Medium· 5.6
2y ago

Requests `Session` object does not verify requests after making first request with verify=False

Requests `Session` object does not verify requests after making first request with verify=False

▾ Sunlitrequests · requestsEPSS 0.34%via OSV
CVE-2021-47431Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix gart.bo pin_count leak gmc_v{9,10}_0_gart_disable() isn't called matched with correspoding gart_enbale function in SRIOV case

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix gart.bo pin_count leak gmc_v{9,10}_0_gart_disable() isn't called matched with correspoding gart_enbale function in SRIOV case. This will lead to gart.b…

▾ Sunlitlinux · linux_kernelEPSS 0.22%via NVD
CVE-2021-47410Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix svm_migrate_fini warning Device manager releases device-specific resources when a driver disconnects from a device, devm_memunmap_pages and devm_releas…

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix svm_migrate_fini warning Device manager releases device-specific resources when a driver disconnects from a device, devm_memunmap_pages and devm_releas…

▾ Sunlitlinux · linux_kernelEPSS 0.21%via NVD

Most-affected vendors

By CVEs published in the period.