Weekly digest
Week 29, 2024 (15–21 Jul)
22 new CVEs this week, in line with the recent average. Of those, 3 critical and 6 high. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 22 published.
CVE-2024-39907Critical· 9.8PoC1Panel has an SQL injection issue related to the orderBy clause
1Panel has an SQL injection issue related to the orderBy clause
CVE-2024-39700Critical· 9.8PoCJupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension author…
CVE-2024-35198Critical· 9.8TorchServe vulnerable to bypass of allowed_urls configuration
TorchServe vulnerable to bypass of allowed_urls configuration
CVE-2024-39877High· 8.8Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-6345High· 8.8setuptools vulnerable to Command Injection via package URL
setuptools vulnerable to Command Injection via package URL
CVE-2024-39123Medium· 5.4PoCCalibre-Web Cross Site Scripting (XSS)
Calibre-Web Cross Site Scripting (XSS)
CVE-2024-21527High· 8.2Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/…
Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/…
CVE-2024-35199High· 8.2TorchServe gRPC Port Exposure
TorchServe gRPC Port Exposure
CVE-2024-41122High· 7.5Woodpecker's custom environment variables allow to alter execution flow of plugins
Woodpecker's custom environment variables allow to alter execution flow of plugins
CVE-2024-6281High· 7.3LoLLMS vulnerable to Expected Behavior Violation
LoLLMS vulnerable to Expected Behavior Violation
CVE-2024-39887Medium· 4.3PoCApache Superset vulnerable to improper SQL authorization
Apache Superset vulnerable to improper SQL authorization
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
Kubernetes sets incorrect permissions on Windows containers logs
Most-affected vendors
By CVEs published in the period.