VulnSea

Weekly digest

Week 22, 2024 (27 May – 2 Jun)

16 new CVEs this week, in line with the recent average. Of those, 1 critical and 2 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

16
New CVEs
1
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2024-23692Critical· 9.8CISA KEVPoC
2y ago

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…

▾ Hadalrejetto · http_file_serverEPSS 99%via NVD
CVE-2024-24919High· 8.6CISA KEVPoC
2y ago

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…

▾ Abyssalcheckpoint · cloudguard_network_securityEPSS 100%via NVD
CVE-2024-36110High· 8.2
2y ago

ansibleguy-webui Cross-site Scripting vulnerability

ansibleguy-webui Cross-site Scripting vulnerability

▾ Twilightansibleguy-webui · ansibleguy-webuiEPSS 0.40%via OSV
CVE-2024-35189Medium· 6.5
2y ago

Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints

Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.58%via OSV
CVE-2024-2199Medium· 5.7
2y ago

A denial of service vulnerability was found in 389-ds-base ldap server

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.

▾ SunlitEPSS 0.56%via NVD
CVE-2024-35228Medium· 5.5
2y ago

Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`

Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`

▾ Sunlitwagtail · wagtailEPSS 0.33%via OSV
CVE-2024-36903Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check …

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check …

▾ Sunlitlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-36105Medium· 5.3
2y ago

dbt allows Binding to an Unrestricted IP Address via socketsocket

dbt allows Binding to an Unrestricted IP Address via socketsocket

▾ Sunlitdbt-core · dbt-coreEPSS 0.71%via OSV
CVE-2022-4969Medium· 5.3
2y ago

rockhopper Buffer Overflow vulnerability

rockhopper Buffer Overflow vulnerability

▾ Sunlitrockhopper · rockhopperEPSS 0.23%via OSV
CVE-2024-36927Medium· 4.7
2y ago

In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]

In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]. __ip_make_skb() tests HDRINCL to know if the skb has icmph…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2024-3924Medium· 4.4
2y ago

code injection vulnerability exists in the huggingface/text-generation-inference repository

code injection vulnerability exists in the huggingface/text-generation-inference repository

▾ Sunlittext-generation · text-generationEPSS 0.32%via OSV
CVE-2024-22244Medium· 4.3
2y ago

Open Redirect URL in Harbor

Open Redirect URL in Harbor

▾ Sunlitgoharbor · github.com/goharbor/harborEPSS 0.36%via OSV

Most-affected vendors

By CVEs published in the period.