Weekly digest
Week 23, 2024 (3–9 Jun)
A heavy week: 41 new CVEs, well above the recent average of about 22. Severity skewed high: 4 critical and 20 high, 59% of the total. 6 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mlflow was the most-affected vendor with 11.
New this week, ranked by depth score
The 12 that matter most of the 41 published.
CVE-2024-5452Critical· 9.8PoCRemote code execution in pytorch lightning
Remote code execution in pytorch lightning
CVE-2024-4325High· 8.6PoCServer-Side Request Forgery in gradio
Server-Side Request Forgery in gradio
CVE-2024-4253Critical· 9.1PoCA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…
CVE-2024-37054High· 8.8PoCMLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-3429Critical· 9.8LoLLMS Path Traversal vulnerability
LoLLMS Path Traversal vulnerability
CVE-2024-37388Critical· 9.1ebookmeta XML External Entity vulnerability
ebookmeta XML External Entity vulnerability
CVE-2024-37061High· 8.8MLFlow improper input validation
MLFlow improper input validation
CVE-2024-37060High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37059High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37058High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37057High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37056High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
Most-affected vendors
By CVEs published in the period.