Weekly digest
Week 45, 2024 (4–10 Nov)
13 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 6 high, 62% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2024-48061Critical· 9.8PoCLangflow vulnerable to remote code execution
Langflow vulnerable to remote code execution
CVE-2024-51734Critical· 9.1Access control vulnerable to user data deletion by anonynmous users
Access control vulnerable to user data deletion by anonynmous users
CVE-2024-51998High· 8.6changedetection.io path traversal using file URI scheme without supplying hostname
changedetection.io path traversal using file URI scheme without supplying hostname
CVE-2024-9902Medium· 6.3PoCansible-core Incorrect Authorization vulnerability
ansible-core Incorrect Authorization vulnerability
CVE-2024-27529High· 8.4wasm3 uncontrolled memory allocation vulnerability
wasm3 uncontrolled memory allocation vulnerability
CVE-2024-21538High· 7.5Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization
Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program…
CVE-2024-10963High· 7.4A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized acces…
GHSA-p7mv-53f2-4cwjHighCometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
CVE-2024-50164High· 7.1In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonial reported an issue in the BPF verifier where check_mem_size_reg() has the following code: if (!tnum_is_const(re…
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonial reported an issue in the BPF verifier where check_mem_size_reg() has the following code: if (!tnum_is_const(re…
CVE-2024-50378Medium· 6.5Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-48052Medium· 6.5gradio Server Side Request Forgery vulnerability
gradio Server Side Request Forgery vulnerability
CVE-2024-51744Low· 3.1golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…
A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…
Most-affected vendors
By CVEs published in the period.