Weekly digest
Week 44, 2024 (28 Oct – 3 Nov)
15 new CVEs this week, in line with the recent average. Of those, 3 critical and 4 high. 6 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mattermost was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2024-51567Critical· 10.0CISA KEV0dayPoCupgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
CVE-2024-51378Critical· 10.0CISA KEV0dayPoCgetresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
CVE-2024-50623Critical· 9.8CISA KEVPoCIn Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVE-2024-50492High· 8.3PoCImproper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.
CVE-2024-21537High· 8.8Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function
Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious i…
CVE-2024-51483Medium· 6.5PoCchangedetection.io Path Traversal
changedetection.io Path Traversal
CVE-2024-10006High· 8.3hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)
A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).
CVE-2024-8309Medium· 4.9PoCLangchain SQL Injection vulnerability
Langchain SQL Injection vulnerability
CVE-2024-8185High· 7.5Hashicorp Vault vulnerable to denial of service through memory exhaustion
Hashicorp Vault vulnerable to denial of service through memory exhaustion
CVE-2024-49771Medium· 5.3MPXJ has a Potential Path Traversal Vulnerability
MPXJ has a Potential Path Traversal Vulnerability
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
Mattermost Server vulnerable to application crash from attacker-generated large response
Most-affected vendors
By CVEs published in the period.