Weekly digest
Week 22, 2024 (27 May – 2 Jun)
16 new CVEs this week, in line with the recent average. Of those, 1 critical and 2 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-24919High· 8.6CISA KEVPoCPotentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…
CVE-2024-1086High· 7.8CISA KEVPoCA use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
New this week, ranked by depth score
The 12 that matter most of the 16 published.
CVE-2024-23692Critical· 9.8CISA KEVPoCRejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…
CVE-2024-24919High· 8.6CISA KEVPoCPotentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…
CVE-2024-36110High· 8.2ansibleguy-webui Cross-site Scripting vulnerability
ansibleguy-webui Cross-site Scripting vulnerability
CVE-2024-35189Medium· 6.5Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints
Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints
CVE-2024-2199Medium· 5.7A denial of service vulnerability was found in 389-ds-base ldap server
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
CVE-2024-35228Medium· 5.5Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
CVE-2024-36903Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check …
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check …
CVE-2024-36105Medium· 5.3dbt allows Binding to an Unrestricted IP Address via socketsocket
dbt allows Binding to an Unrestricted IP Address via socketsocket
CVE-2022-4969Medium· 5.3rockhopper Buffer Overflow vulnerability
rockhopper Buffer Overflow vulnerability
CVE-2024-36927Medium· 4.7In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]
In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]. __ip_make_skb() tests HDRINCL to know if the skb has icmph…
CVE-2024-3924Medium· 4.4code injection vulnerability exists in the huggingface/text-generation-inference repository
code injection vulnerability exists in the huggingface/text-generation-inference repository
CVE-2024-22244Medium· 4.3Open Redirect URL in Harbor
Open Redirect URL in Harbor
Most-affected vendors
By CVEs published in the period.