Weekly digest
Week 28, 2024 (8–14 Jul)
22 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 11 high, 55% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. django was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 22 published.
CVE-2024-39903High· 8.6PoCLocal File Inclusion in Solara
Local File Inclusion in Solara
CVE-2024-39614High· 7.5PoCDjango vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-6037Critical· 9.1A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…
CVE-2024-6409High· 7.0A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd)
A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this…
CVE-2024-4944High· 7.8A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.
CVE-2024-5971High· 7.5A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of…
CVE-2024-6468High· 7.5Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
Django Path Traversal vulnerability
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-6227High· 7.5Aim denial of service vulnerability
Aim denial of service vulnerability
CVE-2024-39896High· 7.5Directus Allows Single Sign-On User Enumeration
Directus Allows Single Sign-On User Enumeration
CVE-2024-5974High· 7.2A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 …
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 …
Most-affected vendors
By CVEs published in the period.