VulnSea

Weekly digest

Week 32, 2024 (5–11 Aug)

13 new CVEs this week, in line with the recent average. Of those, 1 critical and 4 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mozilla was the most-affected vendor with 4.

13
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2024-6886Critical· 10.0PoC
2y ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

▾ AbyssalGitea · Gitea Open Source Git ServerEPSS 33%via NVD
CVE-2024-6984High· 8.8
2y ago

Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm

Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm

▾ Twilightjuju · github.com/juju/jujuEPSS 0.38%via OSV
CVE-2024-7523High· 8.1
2y ago

A select option could partially obscure security prompts

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

▾ Twilightmozilla · firefox_mobileEPSS 0.27%via NVD
CVE-2024-7409High· 7.5
2y ago

A flaw was found in the QEMU NBD Server

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

▾ TwilightEPSS 1.0%via NVD
CVE-2024-41942High· 7.2
2y ago

JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

▾ Twilightjupyterhub · jupyterhubEPSS 0.59%via OSV
CVE-2024-7143Medium· 6.7
2y ago

Pulp incorrectly assigns RBAC permissions in tasks that create objects

Pulp incorrectly assigns RBAC permissions in tasks that create objects

▾ Sunlitpulpcore · pulpcoreEPSS 0.61%via OSV
CVE-2024-6706Medium· 6.1
2y ago

Open WebUI Stored Cross-Site Scripting Vulnerability

Open WebUI Stored Cross-Site Scripting Vulnerability

▾ Sunlitopen-webui · open-webuiEPSS 0.66%via OSV
CVE-2024-43113Medium· 6.1
2y ago

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

▾ Sunlitmozilla · firefox_mobileEPSS 0.25%via NVD
CVE-2024-43112Medium· 6.1
2y ago

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

▾ Sunlitmozilla · firefox_mobileEPSS 0.25%via NVD
CVE-2024-43111Medium· 6.1
2y ago

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

▾ Sunlitmozilla · firefox_mobileEPSS 0.27%via NVD
CVE-2024-42367Medium· 4.8
2y ago

In aiohttp, compressed files as symlinks are not protected from path traversal

In aiohttp, compressed files as symlinks are not protected from path traversal

▾ Sunlitaiohttp · aiohttpEPSS 0.65%via OSV
CVE-2024-20479Medium· 4.8
2y ago

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-su…

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-su…

▾ Sunlitcisco · identity_services_engineEPSS 0.29%via NVD

Most-affected vendors

By CVEs published in the period.