VulnSea

Weekly digest

Week 39, 2024 (23–29 Sep)

8 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 3 high, 75% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. watchguard was the most-affected vendor with 3.

8
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2024-6592Critical· 9.1PoC
2y ago

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

▾ Abyssalwatchguard · authentication_gatewayEPSS 1.2%via NVD
CVE-2024-9014High· 8.6PoC
2y ago

OAuth2 client ID and secret exposed through the web browser

OAuth2 client ID and secret exposed through the web browser

▾ Midnightpgadmin4 · pgadmin4EPSS 9.7%via OSV
CVE-2024-6593Critical· 9.1
2y ago

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…

▾ Midnightwatchguard · authentication_gatewayEPSS 0.58%via NVD
CVE-2024-46488Critical· 9.1
2y ago

Heap-based Buffer Overflow in sqlite-vec

Heap-based Buffer Overflow in sqlite-vec

▾ Midnightsqlite-vec · sqlite-vecEPSS 0.44%via OSV
CVE-2024-7594High· 7.5
2y ago

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.27%via OSV
CVE-2024-6594High· 7.5
2y ago

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denia…

▾ Twilightwatchguard · single_sign-on_clientEPSS 0.63%via NVD
CVE-2024-47003Medium· 5.4
2y ago

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.58%via OSV
CVE-2024-9277Low· 3.5
2y ago

Inefficient Regular Expression Complexity in langflow

Inefficient Regular Expression Complexity in langflow

▾ Sunlitlangflow · langflowEPSS 0.96%via OSV

Most-affected vendors

By CVEs published in the period.