VulnSea

Weekly digest

Week 26, 2024 (24–30 Jun)

22 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 10 high, 59% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. lollms was the most-affected vendor with 4.

22
New CVEs
3
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2024-6127Critical· 9.8PoC
2y ago

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all crypt…

▾ AbyssalEPSS 10%via NVD
CVE-2024-5751Critical· 9.8PoC
2y ago

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…

▾ Abyssallitellm · litellmEPSS 0.88%via NVD
CVE-2024-38526High· 7.2PoC
2y ago

pdoc embeds link to malicious CDN if math mode is enabled

pdoc embeds link to malicious CDN if math mode is enabled

▾ Midnightpdoc · pdocEPSS 3.8%via OSV
CVE-2024-5980Critical· 9.1
2y ago

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

▾ Midnightlightning · lightningEPSS 1.3%via OSV
CVE-2024-3121Medium· 6.8PoC
2y ago

Remote Code Execution in create_conda_env function in lollms

Remote Code Execution in create_conda_env function in lollms

▾ Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-6085High· 8.6
2y ago

lollms vulnerable to path traversal due to unauthenticated root folder settings change

lollms vulnerable to path traversal due to unauthenticated root folder settings change

▾ Twilightlollms · lollmsEPSS 0.64%via OSV
CVE-2024-21520Medium· 6.1PoC
2y ago

Cross-site Scripting in djangorestframework

Cross-site Scripting in djangorestframework

▾ Twilightdjangorestframework · djangorestframeworkEPSS 1.1%via OSV
CVE-2024-35260High· 8.0
2y ago

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

▾ Twilightmicrosoft · power_platformEPSS 0.83%via NVD
CVE-2024-22232High· 7.7
2y ago

Path traversal in saltstack

Path traversal in saltstack

▾ Twilightsalt · saltEPSS 0.84%via OSV
CVE-2024-39705High· 7.5
2y ago

ntlk unsafe deserialization vulnerability

ntlk unsafe deserialization vulnerability

▾ Twilightnltk · nltkEPSS 1.3%via OSV
CVE-2024-6090High· 7.5
2y ago

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histo…

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target s…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.86%via OSV
CVE-2024-6038High· 7.5
2y ago

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-p…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.66%via OSV

Most-affected vendors

By CVEs published in the period.