VulnSea

Weekly digest

Week 25, 2024 (17–23 Jun)

A quiet week: only 14 new CVEs against a recent average of about 28. Of those, 3 high. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

14
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2024-28397High· 8.8PoC
2y ago

js2py allows remote code execution

js2py allows remote code execution

▾ Midnightjs2py · js2pyEPSS 4.5%via OSV
CVE-2024-38355Medium· 7.3PoC
2y ago

socket.io has an unhandled 'error' event

socket.io has an unhandled 'error' event

▾ Twilightsocket.io · socket.ioEPSS 0.81%via GHSA
CVE-2024-34693Medium· 6.8PoC
2y ago

Apache Superset server arbitrary file read

Apache Superset server arbitrary file read

▾ Twilightapache-superset · apache-supersetEPSS 1.6%via OSV
CVE-2024-38620High· 8.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP con…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP con…

▾ Twilightlinux · linux_kernelEPSS 0.31%via NVD
CVE-2024-34694High· 8.1
2y ago

LNbits improperly handles potential network and payment failures when using Eclair backend

LNbits improperly handles potential network and payment failures when using Eclair backend

▾ Twilightlnbits · lnbitsEPSS 0.60%via OSV
CVE-2024-4940Medium· 5.4PoC
2y ago

Open redirect in gradio

Open redirect in gradio

▾ Twilightgradio · gradioEPSS 1.0%via OSV
CVE-2024-38357Medium· 6.1
2y ago

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

▾ Sunlittinymce · tinymceEPSS 0.53%via OSV
CVE-2024-38356Medium· 6.1
2y ago

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

▾ Sunlittinymce · tinymceEPSS 0.53%via OSV
CVE-2024-35768Medium· 5.9
2y ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Co…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Co…

▾ Sunlitblueastral · page_builder:_live_composerEPSS 0.32%via NVD
GHSA-rvj4-q8q5-8grfMedium· 5.5
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

▾ Sunlittraefik · github.com/traefik/traefik/v3via OSV
CVE-2021-47610Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null ptr access msm_ioctl_gem_submit() Fix the below null pointer dereference in msm_ioctl_gem_submit(): 26545.260705: Call trace: 26545.263223: k…

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null ptr access msm_ioctl_gem_submit() Fix the below null pointer dereference in msm_ioctl_gem_submit(): 26545.260705: Call trace: 26545.263223: k…

▾ Sunlitlinux · linux_kernelEPSS 0.19%via NVD
CVE-2024-38082Medium· 4.7
2y ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

▾ Sunlitmicrosoft · edgeEPSS 0.50%via NVD

Most-affected vendors

By CVEs published in the period.