Weekly digest
Week 21, 2024 (20–26 May)
23 new CVEs this week, in line with the recent average. Of those, 3 critical and 4 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 6.
New this week, ranked by depth score
The 12 that matter most of the 23 published.
CVE-2024-36039Critical· 9.8PoCPyMySQL SQL Injection vulnerability
PyMySQL SQL Injection vulnerability
CVE-2024-35059Critical· 9.8NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-35056Critical· 9.8NASA AIT-Core vulnerable to SQL Injection
NASA AIT-Core vulnerable to SQL Injection
CVE-2024-35058High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-35057High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-35061High· 7.3NASA AIT-Core uses unencrypted channels to exchange data over the network
NASA AIT-Core uses unencrypted channels to exchange data over the network
CVE-2021-47354High· 7.1In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.
CVE-2024-36013Medium· 6.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type vo…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type vo…
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
OMERO.web must check that the JSONP callback is a valid function
CVE-2024-35195Medium· 5.6Requests `Session` object does not verify requests after making first request with verify=False
Requests `Session` object does not verify requests after making first request with verify=False
CVE-2021-47431Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix gart.bo pin_count leak gmc_v{9,10}_0_gart_disable() isn't called matched with correspoding gart_enbale function in SRIOV case
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix gart.bo pin_count leak gmc_v{9,10}_0_gart_disable() isn't called matched with correspoding gart_enbale function in SRIOV case. This will lead to gart.b…
CVE-2021-47410Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix svm_migrate_fini warning Device manager releases device-specific resources when a driver disconnects from a device, devm_memunmap_pages and devm_releas…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix svm_migrate_fini warning Device manager releases device-specific resources when a driver disconnects from a device, devm_memunmap_pages and devm_releas…
Most-affected vendors
By CVEs published in the period.