Weekly digest
Week 48, 2024 (25 Nov – 1 Dec)
17 new CVEs this week, in line with the recent average. Of those, 2 critical and 5 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Red Hat was the most-affected vendor with 4.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 17 published.
CVE-2024-11680Critical· 9.8CISA KEVPoCProjectSend versions prior to r1720 are affected by an improper authentication vulnerability
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …
CVE-2024-11667High· 7.5CISA KEVA directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…
CVE-2024-53920High· 7.8PoCIn elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…
CVE-2024-52787Critical· 9.1libre-chat Path Traversal vulnerability
libre-chat Path Traversal vulnerability
CVE-2024-52336High· 7.8A script injection vulnerability was identified in the Tuned package
A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus…
CVE-2024-8676High· 7.4A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it
A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead…
CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement
OpenStack Neutron can use an incorrect ID during policy enforcement
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
Moby Race Condition vulnerability
CVE-2024-53859Medium· 6.5`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
CVE-2024-10270Medium· 6.5A vulnerability was found in the Keycloak-services package
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
CVE-2024-53597Medium· 6.3masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.
masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.
CVE-2024-39162Medium· 6.1pyspider Cross-site Scripting vulnerability
pyspider Cross-site Scripting vulnerability
Most-affected vendors
By CVEs published in the period.