Weekly digest
Week 49, 2024 (2–8 Dec)
18 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 11 high, 67% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. matrix-synapse was the most-affected vendor with 4.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-51378Critical· 10.0CISA KEV0dayPoCgetresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
CVE-2024-11680Critical· 9.8CISA KEVPoCProjectSend versions prior to r1720 are affected by an improper authentication vulnerability
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …
CVE-2024-11667High· 7.5CISA KEVA directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…
New this week, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2024-52270High· 8.2PoCPDF Document Spoofing in DropBox Sign(HelloSign)
User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrom…
CVE-2024-53908Critical· 9.8Django SQL injection in HasKey(lhs, rhs) on Oracle
Django SQL injection in HasKey(lhs, rhs) on Oracle
CVE-2024-39163High· 8.8pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints
pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints
CVE-2024-53865High· 8.2Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
CVE-2024-54216High· 7.7Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForms: from n/a before 7.0.2.
Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForms: from n/a before 7.0.2.
CVE-2024-53907High· 7.5Django denial-of-service in django.utils.html.strip_tags()
Django denial-of-service in django.utils.html.strip_tags()
CVE-2024-12254High· 7.5Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"
Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark". Because of t…
CVE-2024-53863HighSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2024-52815HighSynapse allows a a malformed invite to break the invitee's `/sync`
Synapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-52805HighSynapse allows unsupported content types to lead to memory exhaustion
Synapse allows unsupported content types to lead to memory exhaustion
CVE-2024-53981High· 7.5Denial of service (DoS) via deformation `multipart/form-data` boundary
Denial of service (DoS) via deformation `multipart/form-data` boundary
CVE-2024-53848High· 7.1check-jsonschema default caching for remote schemas allows for cache confusion
check-jsonschema default caching for remote schemas allows for cache confusion
Most-affected vendors
By CVEs published in the period.