VulnSea

Weekly digest

Week 36, 2024 (2–8 Sep)

16 new CVEs this week, in line with the recent average. Of those, 1 critical and 3 high. No new KEV entries. opensc_project was the most-affected vendor with 6.

16
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2024-45053Critical· 9.1
2y ago

Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine

Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine

▾ Midnightethyca-fides · ethyca-fidesEPSS 1.3%via OSV
CVE-2024-45498High· 8.8
2y ago

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

▾ Twilightapache-airflow · apache-airflowEPSS 1.2%via OSV
CVE-2024-45034High· 8.8
2y ago

Apache Airflow vulnerable to Execution with Unnecessary Privileges

Apache Airflow vulnerable to Execution with Unnecessary Privileges

▾ Twilightapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-8418High· 7.5
2y ago

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to b…

▾ Twilightcontainers · aardvark-dnsEPSS 0.77%via NVD
GHSA-h4gh-qq45-vh27Medium
2y ago

pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels

pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels

▾ Sunlitcryptography · cryptographyvia OSV
CVE-2024-45619Medium· 4.3
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are…

▾ Sunlitopensc_project · openscEPSS 0.33%via NVD
CVE-2024-45620Low· 3.9
2y ago

A vulnerability was found in the pkcs15-init tool in OpenSC

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data…

▾ Sunlitopensc_project · openscEPSS 0.32%via NVD
CVE-2024-45618Low· 3.9
2y ago

A vulnerability was found in pkcs15-init in OpenSC

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values …

▾ Sunlitopensc_project · openscEPSS 0.31%via NVD
CVE-2024-45617Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient o…

▾ Sunlitopensc_project · openscEPSS 0.30%via NVD
CVE-2024-45616Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following …

▾ Sunlitopensc_project · openscEPSS 0.36%via NVD
CVE-2024-45615Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

▾ Sunlitopensc_project · openscEPSS 0.36%via NVD
CVE-2024-45314Low· 3.6
2y ago

Flask-AppBuilder's login form allows browser to cache sensitive fields

Flask-AppBuilder's login form allows browser to cache sensitive fields

▾ Sunlitflask-appbuilder · flask-appbuilderEPSS 0.27%via OSV

Most-affected vendors

By CVEs published in the period.