VulnSea

Weekly digest

Week 29, 2024 (15–21 Jul)

22 new CVEs this week, in line with the recent average. Of those, 3 critical and 6 high. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 3.

22
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2024-39907Critical· 9.8PoC
2y ago

1Panel has an SQL injection issue related to the orderBy clause

1Panel has an SQL injection issue related to the orderBy clause

▾ Abyssal1Panel-dev · github.com/1Panel-dev/1PanelEPSS 29%via OSV
CVE-2024-39700Critical· 9.8PoC
2y ago

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension author…

▾ Abyssaljupyterlab · jupyterlabEPSS 1.1%via OSV
CVE-2024-35198Critical· 9.8
2y ago

TorchServe vulnerable to bypass of allowed_urls configuration

TorchServe vulnerable to bypass of allowed_urls configuration

▾ Midnighttorchserve · torchserveEPSS 0.80%via OSV
CVE-2024-39877High· 8.8
2y ago

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

▾ Twilightapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-6345High· 8.8
2y ago

setuptools vulnerable to Command Injection via package URL

setuptools vulnerable to Command Injection via package URL

▾ Twilightsetuptools · setuptoolsEPSS 1.9%via OSV
CVE-2024-39123Medium· 5.4PoC
2y ago

Calibre-Web Cross Site Scripting (XSS)

Calibre-Web Cross Site Scripting (XSS)

▾ Twilightcalibreweb · calibrewebEPSS 23%via OSV
CVE-2024-21527High· 8.2
2y ago

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/…

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/…

▾ TwilightEPSS 0.57%via NVD
CVE-2024-35199High· 8.2
2y ago

TorchServe gRPC Port Exposure

TorchServe gRPC Port Exposure

▾ Twilighttorchserve · torchserveEPSS 0.64%via OSV
CVE-2024-41122High· 7.5
2y ago

Woodpecker's custom environment variables allow to alter execution flow of plugins

Woodpecker's custom environment variables allow to alter execution flow of plugins

▾ Twilightwoodpecker · go.woodpecker-ci.org/woodpecker/v2EPSS 0.62%via OSV
CVE-2024-6281High· 7.3
2y ago

LoLLMS vulnerable to Expected Behavior Violation

LoLLMS vulnerable to Expected Behavior Violation

▾ Twilightlollms · lollmsEPSS 0.27%via OSV
CVE-2024-39887Medium· 4.3PoC
2y ago

Apache Superset vulnerable to improper SQL authorization

Apache Superset vulnerable to improper SQL authorization

▾ Twilightapache-superset · apache-supersetEPSS 4.4%via OSV
CVE-2024-5321Medium· 6.1
2y ago

Kubernetes sets incorrect permissions on Windows containers logs

Kubernetes sets incorrect permissions on Windows containers logs

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.31%via OSV

Most-affected vendors

By CVEs published in the period.