VulnSea

Weekly digest

Week 49, 2024 (2–8 Dec)

18 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 11 high, 67% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. matrix-synapse was the most-affected vendor with 4.

18
New CVEs
1
Critical
3
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2024-51378Critical· 10.0CISA KEV0dayPoC
1y ago

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

▾ Hadalcyberpanel · cyberpanelEPSS 95%via NVD
CVE-2024-11680Critical· 9.8CISA KEVPoC
1y ago

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …

▾ Hadalprojectsend · projectsendEPSS 92%via NVD
CVE-2024-11667High· 7.5CISA KEV
1y ago

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…

▾ Abyssalzyxel · zldEPSS 2.9%via NVD

New this week, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2024-52270High· 8.2PoC
1y ago

PDF Document Spoofing in DropBox Sign(HelloSign)

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrom…

▾ MidnightDropBox(HelloSign) · DropBox SignEPSS 0.19%via CVEORG
CVE-2024-53908Critical· 9.8
1y ago

Django SQL injection in HasKey(lhs, rhs) on Oracle

Django SQL injection in HasKey(lhs, rhs) on Oracle

▾ Midnightdjango · djangoEPSS 1.4%via OSV
CVE-2024-39163High· 8.8
1y ago

pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints

pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints

▾ Twilightpyspider · pyspiderEPSS 0.23%via OSV
CVE-2024-53865High· 8.2
1y ago

Python package "zhmcclient" stores passwords in clear text in its HMC and API logs

Python package "zhmcclient" stores passwords in clear text in its HMC and API logs

▾ Twilightzhmcclient · zhmcclientEPSS 0.14%via OSV
CVE-2024-54216High· 7.7
1y ago

Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForms: from n/a before 7.0.2.

Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForms: from n/a before 7.0.2.

▾ Twilightreputeinfosystems · arformsEPSS 0.55%via NVD
CVE-2024-53907High· 7.5
1y ago

Django denial-of-service in django.utils.html.strip_tags()

Django denial-of-service in django.utils.html.strip_tags()

▾ Twilightdjango · djangoEPSS 1.4%via OSV
CVE-2024-12254High· 7.5
1y ago

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark". Because of t…

▾ TwilightEPSS 1.9%via NVD
CVE-2024-53863High
1y ago

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.61%via OSV
CVE-2024-52815High
1y ago

Synapse allows a a malformed invite to break the invitee's `/sync`

Synapse allows a a malformed invite to break the invitee's `/sync`

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.57%via OSV
CVE-2024-52805High
1y ago

Synapse allows unsupported content types to lead to memory exhaustion

Synapse allows unsupported content types to lead to memory exhaustion

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.74%via OSV
CVE-2024-53981High· 7.5
1y ago

Denial of service (DoS) via deformation `multipart/form-data` boundary

Denial of service (DoS) via deformation `multipart/form-data` boundary

▾ Twilightpython-multipart · python-multipartEPSS 0.64%via OSV
CVE-2024-53848High· 7.1
1y ago

check-jsonschema default caching for remote schemas allows for cache confusion

check-jsonschema default caching for remote schemas allows for cache confusion

▾ Twilightcheck-jsonschema · check-jsonschemaEPSS 0.14%via OSV

Most-affected vendors

By CVEs published in the period.