Weekly digest
Week 34, 2024 (19–25 Aug)
A busier-than-usual week with 20 new CVEs (recent average about 15). Of those, 2 critical and 6 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. mage-ai was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 20 published.
CVE-2024-40766Critical· 9.8CISA KEVPoCAn improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…
CVE-2024-45163Critical· 9.1PoCThe Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server
The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized usern…
CVE-2024-43406High· 8.8LF Edge eKuiper has a SQL Injection in sqlKvStore
LF Edge eKuiper has a SQL Injection in sqlKvStore
CVE-2024-6508High· 8.0An insufficient entropy vulnerability was found in the Openshift Console
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is u…
CVE-2024-43399High· 8.0Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
CVE-2024-7885High· 7.5A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTT…
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4
Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.
CVE-2024-45187High· 7.1Mage AI incorrectly gives privileges to users with deleted accounts
Mage AI incorrectly gives privileges to users with deleted accounts
CVE-2024-41675Medium· 6.8CKAN has Cross-site Scripting vector in the Datatables view plugin
CKAN has Cross-site Scripting vector in the Datatables view plugin
CVE-2024-45190Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-45189Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-45188Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
Most-affected vendors
By CVEs published in the period.