VulnSea

Weekly digest

Week 31, 2024 (29 Jul – 4 Aug)

17 new CVEs this week, in line with the recent average. Of those, 7 high. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 5.

17
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2024-7340High· 8.8PoC
2y ago

Weave server API vulnerable to arbitrary file leak

Weave server API vulnerable to arbitrary file leak

▾ Midnightweave · weaveEPSS 5.0%via OSV
CVE-2024-41062High· 8.8
2y ago

bluetooth/l2cap: sync sock recv cb and release

In the Linux kernel, the following vulnerability has been resolved: bluetooth/l2cap: sync sock recv cb and release The problem occurs between the system call to close the sock and hci_rx_work, where the former releases the sock and the…

▾ TwilightLinux · LinuxEPSS 0.31%via CVEORG
CVE-2024-41671High· 8.3
2y ago

twisted.web has disordered HTTP pipeline response

twisted.web has disordered HTTP pipeline response

▾ Twilighttwisted · twistedEPSS 0.86%via OSV
CVE-2024-42088High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") rem…

In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") rem…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-41955Medium· 5.2PoC
2y ago

MobSF vulnerable to Open Redirect in Login Redirect

MobSF vulnerable to Open Redirect in Login Redirect

▾ Twilightmobsf · mobsfEPSS 1.0%via OSV
CVE-2024-41950High· 7.5
2y ago

Insecure Jinja2 templates rendered in Haystack Components can lead to RCE

Insecure Jinja2 templates rendered in Haystack Components can lead to RCE

▾ Twilighthaystack-ai · haystack-aiEPSS 1.2%via OSV
CVE-2023-33976High· 7.5
2y ago

TensorFlow has segfault in array_ops.upper_bound

TensorFlow has segfault in array_ops.upper_bound

▾ Twilighttensorflow · tensorflowEPSS 0.43%via OSV
CVE-2024-42132High· 7.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida a…

In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida a…

▾ Twilightlinux · linux_kernelEPSS 0.29%via NVD
CVE-2024-37129Medium· 6.7
2y ago

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.

▾ Sunlitdell · inventory_collectorEPSS 0.17%via NVD
CVE-2024-6578Medium· 6.1
2y ago

Aim Stored Cross-site Scripting Vulnerability

Aim Stored Cross-site Scripting Vulnerability

▾ Sunlitaim · aimEPSS 0.29%via OSV
CVE-2024-41255Medium· 5.9
2y ago

Filestash configured to skip TLS certificate verification when using the FTPS protocol

Filestash configured to skip TLS certificate verification when using the FTPS protocol

▾ Sunlitmickael-kerjean · github.com/mickael-kerjean/filestashEPSS 0.26%via OSV
CVE-2024-37286Medium· 5.7
2y ago

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

▾ Sunlitelastic · github.com/elastic/apm-serverEPSS 0.49%via OSV

Most-affected vendors

By CVEs published in the period.