VulnSea

Weekly digest

Week 46, 2024 (11–17 Nov)

A busier-than-usual week with 17 new CVEs (recent average about 14). Of those, 2 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. calibreweb was the most-affected vendor with 3.

17
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2024-49039High· 8.8CISA KEV0dayPoC
1y ago

Windows Task Scheduler Elevation of Privilege Vulnerability

Windows Task Scheduler Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 14%via NVD
CVE-2024-45784High· 7.5
1y ago

Apache Airflow: Sensitive configuration values are not masked in the logs by default

Apache Airflow: Sensitive configuration values are not masked in the logs by default

▾ Twilightairflow · airflowEPSS 1.3%via OSV
CVE-2023-34049Medium· 6.7
1y ago

Salt preflight script could be attacker controlled

Salt preflight script could be attacker controlled

▾ Sunlitsalt · saltEPSS 0.19%via OSV
CVE-2024-49393Medium· 6.5
1y ago

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message con…

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message con…

▾ Sunlitmutt · muttEPSS 0.33%via NVD
CVE-2021-3988Medium· 6.1
1y ago

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.36%via OSV
CVE-2023-6110Medium· 5.5
1y ago

OpenStack improperly deletes access rules

OpenStack improperly deletes access rules

▾ Sunlitpython-openstackclient · python-openstackclientEPSS 0.49%via OSV
CVE-2021-3987Medium· 5.4
1y ago

Improper Access Control in janeczku/calibre-web

Improper Access Control in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.35%via OSV
CVE-2024-4311Medium· 5.4
1y ago

Missing ratelimit on passwrod resets in zenml

Missing ratelimit on passwrod resets in zenml

▾ Sunlitzenml · zenmlEPSS 0.48%via OSV
CVE-2024-11079Medium· 5.5
1y ago

A flaw was found in Ansible-Core

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote da…

▾ Sunlitansible-core · ansible-coreEPSS 0.50%via NVD
RUSTSEC-2024-0401Medium· 5.3
1y ago

Denial of service because of stack overflow with malicious decompression input

Denial of service because of stack overflow with malicious decompression input

▾ Sunlitzlib-rs · zlib-rsvia OSV
CVE-2024-49395Medium· 5.3
1y ago

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

▾ Sunlitmutt · muttEPSS 0.30%via NVD
CVE-2024-49394Medium· 5.3
1y ago

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

▾ Sunlitmutt · muttEPSS 0.33%via NVD

Most-affected vendors

By CVEs published in the period.