VulnSea

Weekly digest

Week 30, 2024 (22–28 Jul)

A quiet week: only 11 new CVEs against a recent average of about 26. Of those, 2 critical and 1 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. anki was the most-affected vendor with 3.

11
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 11 that matter most of the 11 published.

MAL-2024-12279Critical⚠ Exploited
2y ago

Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)

Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)

▾ Abyssalgoogle-cloud-datacatalog-lineage-producer-client · google-cloud-datacatalog-lineage-producer-clientvia OSV
CVE-2024-26020Critical· 9.6
2y ago

Ankitects Anki arbitrary script execution vulnerability

Ankitects Anki arbitrary script execution vulnerability

▾ Midnightanki · ankiEPSS 15%via OSV
CVE-2024-41656High· 7.1
2y ago

Sentry vulnerable to stored Cross-Site Scripting (XSS)

Sentry vulnerable to stored Cross-Site Scripting (XSS)

▾ Twilightsentry · sentryEPSS 0.47%via OSV
CVE-2024-40767Medium· 6.5
2y ago

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

▾ Sunlitnova · novaEPSS 0.94%via OSV
CVE-2024-1724Medium· 6.3
2y ago

snapd failed to restrict writes to the $HOME/bin path

snapd failed to restrict writes to the $HOME/bin path

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.31%via OSV
CVE-2024-29068Medium· 5.8
2y ago

snapd failed to properly check the file type when extracting a snap

snapd failed to properly check the file type when extracting a snap

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.21%via OSV
CVE-2024-29073Medium· 5.3
2y ago

Anki Latex Incomplete Blocklist Vulnerability

Anki Latex Incomplete Blocklist Vulnerability

▾ Sunlitanki · ankiEPSS 12%via OSV
CVE-2024-29069Medium· 4.8
2y ago

snapd failed to properly check the destination of symbolic links when extracting a snap

snapd failed to properly check the destination of symbolic links when extracting a snap

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.23%via OSV
CVE-2024-41666Medium· 4.7
2y ago

The Argo CD web terminal session does not handle the revocation of user permissions properly

The Argo CD web terminal session does not handle the revocation of user permissions properly

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.69%via OSV
CVE-2024-41129Medium· 4.4
2y ago

ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command

ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command

▾ Sunlitops · opsEPSS 0.20%via OSV
CVE-2024-32152Low· 3.1
2y ago

Ankitects Anki LaTeX Blocklist Bypass vulnerability

Ankitects Anki LaTeX Blocklist Bypass vulnerability

▾ Sunlitanki · ankiEPSS 13%via OSV

Most-affected vendors

By CVEs published in the period.