Weekly digest
Week 25, 2024 (17–23 Jun)
A quiet week: only 14 new CVEs against a recent average of about 28. Of those, 3 high. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2024-28397High· 8.8PoCjs2py allows remote code execution
js2py allows remote code execution
CVE-2024-38355Medium· 7.3PoCsocket.io has an unhandled 'error' event
socket.io has an unhandled 'error' event
CVE-2024-34693Medium· 6.8PoCApache Superset server arbitrary file read
Apache Superset server arbitrary file read
CVE-2024-38620High· 8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP con…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP con…
CVE-2024-34694High· 8.1LNbits improperly handles potential network and payment failures when using Eclair backend
LNbits improperly handles potential network and payment failures when using Eclair backend
CVE-2024-4940Medium· 5.4PoCOpen redirect in gradio
Open redirect in gradio
CVE-2024-38357Medium· 6.1TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
CVE-2024-38356Medium· 6.1TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
CVE-2024-35768Medium· 5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Co…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Co…
GHSA-rvj4-q8q5-8grfMedium· 5.5ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
CVE-2021-47610Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null ptr access msm_ioctl_gem_submit() Fix the below null pointer dereference in msm_ioctl_gem_submit(): 26545.260705: Call trace: 26545.263223: k…
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null ptr access msm_ioctl_gem_submit() Fix the below null pointer dereference in msm_ioctl_gem_submit(): 26545.260705: Call trace: 26545.263223: k…
CVE-2024-38082Medium· 4.7Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Most-affected vendors
By CVEs published in the period.