VulnSea

Weekly digest

Week 48, 2024 (25 Nov – 1 Dec)

17 new CVEs this week, in line with the recent average. Of those, 2 critical and 5 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Red Hat was the most-affected vendor with 4.

17
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2024-11680Critical· 9.8CISA KEVPoC
1y ago

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …

▾ Hadalprojectsend · projectsendEPSS 92%via NVD
CVE-2024-11667High· 7.5CISA KEV
1y ago

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…

▾ Abyssalzyxel · zldEPSS 2.9%via NVD
CVE-2024-53920High· 7.8PoC
1y ago

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…

▾ Midnightgnu · emacsEPSS 0.60%via NVD
CVE-2024-52787Critical· 9.1
1y ago

libre-chat Path Traversal vulnerability

libre-chat Path Traversal vulnerability

▾ Midnightlibre-chat · libre-chatEPSS 0.77%via OSV
CVE-2024-52336High· 7.8
1y ago

A script injection vulnerability was identified in the Tuned package

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus…

▾ TwilightEPSS 0.29%via NVD
CVE-2024-8676High· 7.4
1y ago

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead…

▾ TwilightEPSS 0.76%via NVD
CVE-2024-53916High· 7.5
1y ago

OpenStack Neutron can use an incorrect ID during policy enforcement

OpenStack Neutron can use an incorrect ID during policy enforcement

▾ Twilightneutron · neutronEPSS 0.71%via OSV
CVE-2024-36621Medium· 6.5
1y ago

Moby Race Condition vulnerability

Moby Race Condition vulnerability

▾ Sunlitmoby · github.com/moby/mobyEPSS 0.63%via OSV
CVE-2024-53859Medium· 6.5
1y ago

`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace

`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace

▾ Sunlitcli · github.com/cli/go-gh/v2EPSS 0.53%via OSV
CVE-2024-10270Medium· 6.5
1y ago

A vulnerability was found in the Keycloak-services package

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

▾ SunlitRed Hat · keycloakEPSS 1.3%via NVD
CVE-2024-53597Medium· 6.3
1y ago

masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.

masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.

▾ SunlitEPSS 0.31%via NVD
CVE-2024-39162Medium· 6.1
1y ago

pyspider Cross-site Scripting vulnerability

pyspider Cross-site Scripting vulnerability

▾ Sunlitpyspider · pyspiderEPSS 0.41%via OSV

Most-affected vendors

By CVEs published in the period.