Weekly digest
Week 37, 2024 (9–15 Sep)
15 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 9 high, 67% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2024-6587High· 7.5PoCLiteLLM Server-Side Request Forgery (SSRF) vulnerability
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability
MindsDB Cross-site Scripting vulnerability
CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability
MindsDB Eval Injection vulnerability
CVE-2024-21529High· 8.2Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Obj…
CVE-2024-45857High· 7.8Cleanlab Deserialization of Untrusted Data vulnerability
Cleanlab Deserialization of Untrusted Data vulnerability
CVE-2024-27321High· 7.8Refuel Autolab Eval Injection vulnerability
Refuel Autolab Eval Injection vulnerability
CVE-2024-27320High· 7.8Refuel Autolab Eval Injection vulnerability
Refuel Autolab Eval Injection vulnerability
CVE-2024-8751High· 7.5A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface
A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.
CVE-2024-20317High· 7.4Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dr…
CVE-2024-7341High· 7.1A session fixation issue was discovered in the SAML adapters provided by Keycloak
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an …
CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
CVE-2024-8775Medium· 5.5A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…
Most-affected vendors
By CVEs published in the period.