VulnSea

Weekly digest

Week 34, 2024 (19–25 Aug)

A busier-than-usual week with 20 new CVEs (recent average about 15). Of those, 2 critical and 6 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. mage-ai was the most-affected vendor with 5.

20
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2024-40766Critical· 9.8CISA KEVPoC
2y ago

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…

▾ Hadalsonicwall · sonicosEPSS 18%via NVD
CVE-2024-45163Critical· 9.1PoC
2y ago

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized usern…

▾ AbyssalEPSS 0.77%via NVD
CVE-2024-43406High· 8.8
2y ago

LF Edge eKuiper has a SQL Injection in sqlKvStore

LF Edge eKuiper has a SQL Injection in sqlKvStore

▾ Twilightlf-edge · github.com/lf-edge/ekuiperEPSS 0.89%via OSV
CVE-2024-6508High· 8.0
2y ago

An insufficient entropy vulnerability was found in the Openshift Console

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is u…

▾ TwilightEPSS 0.67%via NVD
CVE-2024-43399High· 8.0
2y ago

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

▾ Twilightmobsf · mobsfEPSS 0.96%via OSV
CVE-2024-7885High· 7.5
2y ago

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTT…

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 2.6%via NVD
CVE-2023-7260High· 7.5
2y ago

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

▾ Twilightopentext · cx-e_voiceEPSS 0.52%via NVD
CVE-2024-45187High· 7.1
2y ago

Mage AI incorrectly gives privileges to users with deleted accounts

Mage AI incorrectly gives privileges to users with deleted accounts

▾ Twilightmage-ai · mage-aiEPSS 0.50%via OSV
CVE-2024-41675Medium· 6.8
2y ago

CKAN has Cross-site Scripting vector in the Datatables view plugin

CKAN has Cross-site Scripting vector in the Datatables view plugin

▾ Sunlitckan · ckanEPSS 0.40%via OSV
CVE-2024-45190Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.86%via OSV
CVE-2024-45189Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV
CVE-2024-45188Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV

Most-affected vendors

By CVEs published in the period.