Weekly digest
Week 47, 2024 (18–24 Nov)
A heavy week: 29 new CVEs, well above the recent average of about 13. Severity skewed high: 2 critical and 17 high, 66% of the total. 6 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. cesanta was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-0012Critical· 9.8CISA KEV0dayPoCAn authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
CVE-2024-1212Critical· 10.0CISA KEVPoCUnauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CVE-2024-9474High· 7.2CISA KEV0dayPoCA privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
New this week, ranked by depth score
The 12 that matter most of the 29 published.
CVE-2024-0012Critical· 9.8CISA KEV0dayPoCAn authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
CVE-2024-9474High· 7.2CISA KEV0dayPoCA privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
CVE-2024-11394High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11393High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11392High· 7.50dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-10220High· 8.1PoCKubernetes kubelet arbitrary command execution
Kubernetes kubelet arbitrary command execution
CVE-2024-42450Critical· 10.0The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data
The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Ve…
CVE-2024-53899High· 8.4virtualenv allows command injection through activation scripts for a virtual environment
virtualenv allows command injection through activation scripts for a virtual environment
CVE-2024-7837High· 8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1.
CVE-2024-42386High· 8.2Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
CVE-2024-53063High· 7.8In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: prevent the risk of out of memory access The dvbdev contains a static variable used to store dvb minors. The behavior of it depends if CONFIG_DVB_DYNAM…
In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: prevent the risk of out of memory access The dvbdev contains a static variable used to store dvb minors. The behavior of it depends if CONFIG_DVB_DYNAM…
CVE-2024-52803High· 7.5LLama Factory Remote OS Command Injection Vulnerability
LLama Factory Remote OS Command Injection Vulnerability
Most-affected vendors
By CVEs published in the period.