VulnSea

Weekly digest

Week 38, 2024 (16–22 Sep)

A heavy week: 25 new CVEs, well above the recent average of about 14. Severity skewed high: 3 critical and 10 high, 52% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 3.

25
New CVEs
3
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 25 published.

CVE-2024-8698High· 7.7PoC
2y ago

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position o…

▾ MidnightEPSS 2.0%via NVD
CVE-2024-45496Critical· 9.9
2y ago

A flaw was found in OpenShift

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged securit…

▾ MidnightEPSS 1.0%via NVD
CVE-2024-7387Critical· 9.1
2y ago

A flaw was found in openshift/builder

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” str…

▾ MidnightEPSS 2.3%via NVD
CVE-2024-44004Critical· 9.3
2y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.

▾ Midnightwptaskforce · track_&_traceEPSS 0.46%via NVD
CVE-2024-35515High· 8.8
2y ago

sqlitedict insecure deserialization vulnerability

sqlitedict insecure deserialization vulnerability

▾ Twilightsqlitedict · sqlitedictEPSS 0.89%via OSV
CVE-2024-45858High· 8.8
2y ago

Guardrails has an arbitrary code execution vulnerability

Guardrails has an arbitrary code execution vulnerability

▾ Twilightguardrails-ai · guardrails-aiEPSS 0.38%via OSV
CVE-2024-8883Medium· 6.1PoC
2y ago

A misconfiguration flaw was found in Keycloak

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as author…

▾ Twilightredhat · build_of_keycloakEPSS 2.1%via NVD
CVE-2024-46786High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not de…

In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not de…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-46754High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…

In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2024-46741High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap()…

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap()…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-45601High· 7.5
2y ago

Mesop has a local file Inclusion via static file serving functionality

Mesop has a local file Inclusion via static file serving functionality

▾ Twilightmesop · mesopEPSS 0.28%via OSV
CVE-2024-8768High· 7.5
2y ago

vLLM denial of service vulnerability

vLLM denial of service vulnerability

▾ Twilightvllm · vllmEPSS 0.68%via OSV

Most-affected vendors

By CVEs published in the period.