VulnSea

Weekly digest

Week 45, 2024 (4–10 Nov)

13 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 6 high, 62% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

13
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2024-48061Critical· 9.8PoC
1y ago

Langflow vulnerable to remote code execution

Langflow vulnerable to remote code execution

▾ Abyssallangflow · langflowEPSS 1.5%via OSV
CVE-2024-51734Critical· 9.1
1y ago

Access control vulnerable to user data deletion by anonynmous users

Access control vulnerable to user data deletion by anonynmous users

▾ Midnightaccesscontrol · accesscontrolEPSS 0.43%via OSV
CVE-2024-51998High· 8.6
1y ago

changedetection.io path traversal using file URI scheme without supplying hostname

changedetection.io path traversal using file URI scheme without supplying hostname

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.69%via OSV
CVE-2024-9902Medium· 6.3PoC
1y ago

ansible-core Incorrect Authorization vulnerability

ansible-core Incorrect Authorization vulnerability

▾ Twilightansible-core · ansible-coreEPSS 0.26%via OSV
CVE-2024-27529High· 8.4
1y ago

wasm3 uncontrolled memory allocation vulnerability

wasm3 uncontrolled memory allocation vulnerability

▾ Twilightshareup · github.com/shareup/wasm-interpreter-appleEPSS 0.26%via OSV
CVE-2024-21538High· 7.5
1y ago

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program…

▾ TwilightEPSS 0.87%via NVD
CVE-2024-10963High· 7.4
1y ago

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized acces…

▾ TwilightEPSS 0.78%via NVD
GHSA-p7mv-53f2-4cwjHigh
1y ago

CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data

CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data

▾ Twilightcometbft · github.com/cometbft/cometbftvia OSV
CVE-2024-50164High· 7.1
1y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonial reported an issue in the BPF verifier where check_mem_size_reg() has the following code: if (!tnum_is_const(re…

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonial reported an issue in the BPF verifier where check_mem_size_reg() has the following code: if (!tnum_is_const(re…

▾ Twilightlinux · linux_kernelEPSS 0.21%via NVD
CVE-2024-50378Medium· 6.5
1y ago

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

▾ Sunlitapache-airflow · apache-airflowEPSS 1.2%via OSV
CVE-2024-48052Medium· 6.5
1y ago

gradio Server Side Request Forgery vulnerability

gradio Server Side Request Forgery vulnerability

▾ Sunlitgradio · gradioEPSS 0.47%via OSV
CVE-2024-51744Low· 3.1
1y ago

golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…

A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4.16EPSS 0.51%via CSAF

Most-affected vendors

By CVEs published in the period.