Weekly digest
Week 32, 2024 (5–11 Aug)
13 new CVEs this week, in line with the recent average. Of those, 1 critical and 4 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mozilla was the most-affected vendor with 4.
New this week, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2024-6886Critical· 10.0PoCImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
CVE-2024-6984High· 8.8Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
CVE-2024-7523High· 8.1A select option could partially obscure security prompts
A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.
CVE-2024-7409High· 7.5A flaw was found in the QEMU NBD Server
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
CVE-2024-41942High· 7.2JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
CVE-2024-7143Medium· 6.7Pulp incorrectly assigns RBAC permissions in tasks that create objects
Pulp incorrectly assigns RBAC permissions in tasks that create objects
CVE-2024-6706Medium· 6.1Open WebUI Stored Cross-Site Scripting Vulnerability
Open WebUI Stored Cross-Site Scripting Vulnerability
CVE-2024-43113Medium· 6.1The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
CVE-2024-43112Medium· 6.1Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
CVE-2024-43111Medium· 6.1Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
CVE-2024-42367Medium· 4.8In aiohttp, compressed files as symlinks are not protected from path traversal
In aiohttp, compressed files as symlinks are not protected from path traversal
CVE-2024-20479Medium· 4.8A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-su…
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-su…
Most-affected vendors
By CVEs published in the period.