Weekly digest
Week 26, 2024 (24–30 Jun)
22 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 10 high, 59% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. lollms was the most-affected vendor with 4.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 22 published.
CVE-2024-6127Critical· 9.8PoCBC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all crypt…
CVE-2024-5751Critical· 9.8PoCBerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…
CVE-2024-38526High· 7.2PoCpdoc embeds link to malicious CDN if math mode is enabled
pdoc embeds link to malicious CDN if math mode is enabled
CVE-2024-5980Critical· 9.1pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-3121Medium· 6.8PoCRemote Code Execution in create_conda_env function in lollms
Remote Code Execution in create_conda_env function in lollms
CVE-2024-6085High· 8.6lollms vulnerable to path traversal due to unauthenticated root folder settings change
lollms vulnerable to path traversal due to unauthenticated root folder settings change
CVE-2024-21520Medium· 6.1PoCCross-site Scripting in djangorestframework
Cross-site Scripting in djangorestframework
CVE-2024-35260High· 8.0An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
CVE-2024-22232High· 7.7Path traversal in saltstack
Path traversal in saltstack
CVE-2024-39705High· 7.5ntlk unsafe deserialization vulnerability
ntlk unsafe deserialization vulnerability
CVE-2024-6090High· 7.5A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histo…
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target s…
CVE-2024-6038High· 7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-p…
Most-affected vendors
By CVEs published in the period.