VulnSea

Weekly digest

Week 47, 2024 (18–24 Nov)

A heavy week: 29 new CVEs, well above the recent average of about 13. Severity skewed high: 2 critical and 17 high, 66% of the total. 6 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. cesanta was the most-affected vendor with 5.

29
New CVEs
2
Critical
3
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2024-0012Critical· 9.8CISA KEV0dayPoC
1y ago

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

▾ Hadalpaloaltonetworks · pan-osEPSS 100%via NVD
CVE-2024-1212Critical· 10.0CISA KEVPoC
2y ago

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

▾ Hadalprogress · loadmasterEPSS 95%via NVD
CVE-2024-9474High· 7.2CISA KEV0dayPoC
1y ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 95%via NVD

New this week, ranked by depth score

The 12 that matter most of the 29 published.

CVE-2024-0012Critical· 9.8CISA KEV0dayPoC
1y ago

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

▾ Hadalpaloaltonetworks · pan-osEPSS 100%via NVD
CVE-2024-9474High· 7.2CISA KEV0dayPoC
1y ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 95%via NVD
CVE-2024-11394High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 2.6%via OSV
CVE-2024-11393High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 3.1%via OSV
CVE-2024-11392High· 7.50dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 7.3%via OSV
CVE-2024-10220High· 8.1PoC
1y ago

Kubernetes kubelet arbitrary command execution

Kubernetes kubelet arbitrary command execution

▾ Midnightkubernetes · k8s.io/kubernetesEPSS 3.0%via OSV
CVE-2024-42450Critical· 10.0
1y ago

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Ve…

▾ MidnightEPSS 0.58%via NVD
CVE-2024-53899High· 8.4
1y ago

virtualenv allows command injection through activation scripts for a virtual environment

virtualenv allows command injection through activation scripts for a virtual environment

▾ Twilightvirtualenv · virtualenvEPSS 1.6%via OSV
CVE-2024-7837High· 8.2
1y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1.

▾ TwilightEPSS 0.50%via NVD
CVE-2024-42386High· 8.2
1y ago

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

▾ Twilightcesanta · mongooseEPSS 0.38%via NVD
CVE-2024-53063High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: prevent the risk of out of memory access The dvbdev contains a static variable used to store dvb minors. The behavior of it depends if CONFIG_DVB_DYNAM…

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: prevent the risk of out of memory access The dvbdev contains a static variable used to store dvb minors. The behavior of it depends if CONFIG_DVB_DYNAM…

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2024-52803High· 7.5
1y ago

LLama Factory Remote OS Command Injection Vulnerability

LLama Factory Remote OS Command Injection Vulnerability

▾ Twilightllamafactory · llamafactoryEPSS 2.3%via OSV

Most-affected vendors

By CVEs published in the period.