Weekly digest
Week 30, 2024 (22–28 Jul)
A quiet week: only 11 new CVEs against a recent average of about 26. Of those, 2 critical and 1 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. anki was the most-affected vendor with 3.
New this week, ranked by depth score
The 11 that matter most of the 11 published.
MAL-2024-12279Critical⚠ ExploitedMalicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)
Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)
CVE-2024-26020Critical· 9.6Ankitects Anki arbitrary script execution vulnerability
Ankitects Anki arbitrary script execution vulnerability
CVE-2024-41656High· 7.1Sentry vulnerable to stored Cross-Site Scripting (XSS)
Sentry vulnerable to stored Cross-Site Scripting (XSS)
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2024-1724Medium· 6.3snapd failed to restrict writes to the $HOME/bin path
snapd failed to restrict writes to the $HOME/bin path
CVE-2024-29068Medium· 5.8snapd failed to properly check the file type when extracting a snap
snapd failed to properly check the file type when extracting a snap
CVE-2024-29073Medium· 5.3Anki Latex Incomplete Blocklist Vulnerability
Anki Latex Incomplete Blocklist Vulnerability
CVE-2024-29069Medium· 4.8snapd failed to properly check the destination of symbolic links when extracting a snap
snapd failed to properly check the destination of symbolic links when extracting a snap
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-41129Medium· 4.4ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
CVE-2024-32152Low· 3.1Ankitects Anki LaTeX Blocklist Bypass vulnerability
Ankitects Anki LaTeX Blocklist Bypass vulnerability
Most-affected vendors
By CVEs published in the period.