VulnSea

Weekly digest

Week 33, 2024 (12–18 Aug)

A quiet week: only 5 new CVEs against a recent average of about 16. Severity skewed high: 2 critical and 2 high, 80% of the total. No new KEV entries.

5
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 5 that matter most of the 5 published.

CVE-2024-42467Critical· 10.0
2y ago

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authenti…

▾ Midnightopenhab · openhab_web_interfaceEPSS 1.0%via NVD
CVE-2023-7249Critical· 9.8
2y ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

▾ Midnightopentext · directory_servicesEPSS 0.58%via NVD
CVE-2024-6221High· 7.5
2y ago

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

▾ Twilightflask-cors · flask-corsEPSS 0.72%via OSV
CVE-2024-21801High· 7.1
2y ago

Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.

Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.

▾ Twilightintel · tdx_moduleEPSS 0.18%via NVD
CVE-2024-39283Medium· 6.0
2y ago

Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

▾ Sunlitintel · tdx_moduleEPSS 0.18%via NVD

Most-affected vendors

By CVEs published in the period.