VulnSea

Weekly digest

Week 35, 2024 (26 Aug – 1 Sep)

15 new CVEs this week, in line with the recent average. Of those, 7 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

15
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2021-21401High· 7.1PoC
2y ago

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

▾ Midnightnanopb · nanopbEPSS 1.8%via OSV
GHSA-w2pj-9cgh-mq2cHigh· 8.8
2y ago

opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-contrib-python-headless · opencv-contrib-python-headlessvia OSV
GHSA-qr4w-53vh-m672High· 8.8
2y ago

opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-python · opencv-pythonvia OSV
GHSA-jh2j-j4j9-crg3High· 8.8
2y ago

opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-python-headless · opencv-python-headlessvia OSV
GHSA-cxjf-x6jp-p7mcHigh· 8.8
2y ago

opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-contrib-python · opencv-contrib-pythonvia OSV
CVE-2024-43805High· 7.6
2y ago

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

▾ Twilightjupyterlab · jupyterlabEPSS 0.40%via OSV
CVE-2020-11093High· 7.5
2y ago

Hyperledger Indy's update process of a DID does not check who signs the request

Hyperledger Indy's update process of a DID does not check who signs the request

▾ Twilightindy-node · indy-nodeEPSS 1.2%via OSV
CVE-2024-45509Medium· 6.5
2y ago

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

▾ Sunlitmisp-project · mispEPSS 0.40%via NVD
CVE-2023-26043Medium· 6.5
2y ago

GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection

GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection

▾ Sunlitgeonode · geonodeEPSS 0.84%via OSV
CVE-2024-8105Medium· 6.4
2y ago

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK)

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them…

▾ SunlitEPSS 0.27%via NVD
CVE-2024-42818Medium· 6.1
2y ago

FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function

FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function

▾ Sunlitfastapi-admin · fastapi-adminEPSS 0.29%via OSV
CVE-2024-42816Medium· 6.1
2y ago

FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function

FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function

▾ Sunlitfastapi-admin · fastapi-adminEPSS 0.29%via OSV

Most-affected vendors

By CVEs published in the period.