VulnSea

Weekly digest

Week 28, 2024 (8–14 Jul)

22 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 11 high, 55% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. django was the most-affected vendor with 3.

22
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2024-39903High· 8.6PoC
2y ago

Local File Inclusion in Solara

Local File Inclusion in Solara

▾ Midnightsolara · solaraEPSS 2.9%via OSV
CVE-2024-39614High· 7.5PoC
2y ago

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

▾ Midnightdjango · djangoEPSS 29%via OSV
CVE-2024-6037Critical· 9.1
2y ago

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…

▾ Midnightchuanhuchatgpt · chuanhuchatgptEPSS 11%via OSV
CVE-2024-6409High· 7.0
2y ago

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd)

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this…

▾ TwilightEPSS 28%via NVD
CVE-2024-4944High· 7.8
2y ago

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

▾ Twilightwatchguard · mobile_vpn_with_sslEPSS 0.34%via NVD
CVE-2024-5971High· 7.5
2y ago

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of…

▾ TwilightEPSS 2.9%via NVD
CVE-2024-6468High· 7.5
2y ago

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.49%via OSV
CVE-2024-39330High· 7.5
2y ago

Django Path Traversal vulnerability

Django Path Traversal vulnerability

▾ Twilightdjango · djangoEPSS 1.0%via OSV
CVE-2024-38875High· 7.5
2y ago

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

▾ Twilightdjango · djangoEPSS 1.2%via OSV
CVE-2024-6227High· 7.5
2y ago

Aim denial of service vulnerability

Aim denial of service vulnerability

▾ Twilightaim · aimEPSS 0.58%via OSV
CVE-2024-39896High· 7.5
2y ago

Directus Allows Single Sign-On User Enumeration

Directus Allows Single Sign-On User Enumeration

▾ Twilightdirectus · directusEPSS 0.51%via GHSA
CVE-2024-5974High· 7.2
2y ago

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 …

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 …

▾ Twilightwatchguard · firewareEPSS 1.0%via NVD

Most-affected vendors

By CVEs published in the period.