Weekly digest
Week 42, 2024 (14–20 Oct)
10 new CVEs this week, in line with the recent average. Of those, 2 critical and 2 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-9680Critical· 9.8CISA KEV0dayPoCAn attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…
CVE-2024-30088High· 7.0CISA KEVPoCWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2024-32651Critical· 10.0PoCchangedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
CVE-2024-49604Critical· 9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
CVE-2024-21262Medium· 6.5PoCVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…
CVE-2024-21536High· 7.5Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process …
CVE-2024-21272High· 7.5MySQL Connector/Python connector takeover vulnerability
MySQL Connector/Python connector takeover vulnerability
CVE-2024-21202Medium· 6.1Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated…
CVE-2024-25112Medium· 5.5Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
CVE-2024-24826Medium· 5.5Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
CVE-2024-10073Medium· 5.0Flair allows arbitrary code execution
Flair allows arbitrary code execution
CVE-2024-47874None· 0.0Starlette Denial of service (DoS) via multipart/form-data
Starlette Denial of service (DoS) via multipart/form-data
Most-affected vendors
By CVEs published in the period.