VulnSea

Weekly digest

Week 42, 2024 (14–20 Oct)

10 new CVEs this week, in line with the recent average. Of those, 2 critical and 2 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

10
New CVEs
2
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2024-32651Critical· 10.0PoC
1y ago

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

▾ Abyssalchangedetection-io · changedetection-ioEPSS 84%via OSV
CVE-2024-49604Critical· 9.8
1y ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

▾ Midnightnajeebmedia · memberheroEPSS 0.53%via NVD
CVE-2024-21262Medium· 6.5PoC
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…

▾ Twilightnetapp · oncommand_insightEPSS 0.57%via NVD
CVE-2024-21536High· 7.5
1y ago

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process …

▾ Twilightchimurai · http-proxy-middlewareEPSS 1.0%via NVD
CVE-2024-21272High· 7.5
1y ago

MySQL Connector/Python connector takeover vulnerability

MySQL Connector/Python connector takeover vulnerability

▾ Twilightmysql-connector-python · mysql-connector-pythonEPSS 0.51%via OSV
CVE-2024-21202Medium· 6.1
1y ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated…

▾ Sunlitoracle · peoplesoft_enterprise_peopletoolsEPSS 0.20%via NVD
CVE-2024-25112Medium· 5.5
1y ago

Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder

Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder

▾ Sunlitexiv2 · exiv2EPSS 0.22%via OSV
CVE-2024-24826Medium· 5.5
1y ago

Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder

Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder

▾ Sunlitexiv2 · exiv2EPSS 0.24%via OSV
CVE-2024-10073Medium· 5.0
1y ago

Flair allows arbitrary code execution

Flair allows arbitrary code execution

▾ Sunlitflair · flairEPSS 0.61%via OSV
CVE-2024-47874None· 0.0
1y ago

Starlette Denial of service (DoS) via multipart/form-data

Starlette Denial of service (DoS) via multipart/form-data

▾ Sunlitstarlette · starletteEPSS 0.65%via OSV

Most-affected vendors

By CVEs published in the period.