Weekly digest
Week 35, 2024 (26 Aug – 1 Sep)
15 new CVEs this week, in line with the recent average. Of those, 7 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2021-21401High· 7.1PoCnanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
GHSA-w2pj-9cgh-mq2cHigh· 8.8opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
GHSA-qr4w-53vh-m672High· 8.8opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
GHSA-jh2j-j4j9-crg3High· 8.8opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
GHSA-cxjf-x6jp-p7mcHigh· 8.8opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
CVE-2024-43805High· 7.6HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2020-11093High· 7.5Hyperledger Indy's update process of a DID does not check who signs the request
Hyperledger Indy's update process of a DID does not check who signs the request
CVE-2024-45509Medium· 6.5In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
CVE-2023-26043Medium· 6.5GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
CVE-2024-8105Medium· 6.4A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK)
A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them…
CVE-2024-42818Medium· 6.1FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
CVE-2024-42816Medium· 6.1FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
Most-affected vendors
By CVEs published in the period.