VulnSea

Weekly digest

Week 50, 2024 (9–15 Dec)

18 new CVEs this week, in line with the recent average. Of those, 4 critical and 4 high. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apache-superset was the most-affected vendor with 4.

18
New CVEs
4
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2024-55956Critical· 9.8CISA KEVPoC
1y ago

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…

▾ Hadalcleo · harmonyEPSS 94%via NVD
CVE-2024-55587High· 8.8PoC
1y ago

python-libarchive directory traversal

python-libarchive directory traversal

▾ Midnightpython-libarchive · python-libarchiveEPSS 2.1%via OSV
CVE-2024-53866Critical· 9.8
1y ago

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and insta…

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and insta…

▾ MidnightEPSS 0.98%via NVD
CVE-2024-53947Critical· 9.8
1y ago

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

▾ Midnightapache-superset · apache-supersetEPSS 0.84%via OSV
CVE-2024-55550Low· 2.7CISA KEVPoC
1y ago

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to…

▾ Twilightmitel · micollabEPSS 38%via NVD
CVE-2024-40583Critical· 9.1
1y ago

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

▾ Midnightpentaminds · curovmsEPSS 0.54%via NVD
CVE-2024-52059High· 7.8
1y ago

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags. This issu…

▾ Twilightrti · connext_professionalEPSS 0.17%via NVD
CVE-2024-12397High· 7.4
1y ago

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoo…

▾ TwilightRed Hat · Cryostat 4 on RHEL 9EPSS 0.82%via NVD
CVE-2024-40582High· 7.5
1y ago

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

▾ Twilightpentaminds · curovmsEPSS 0.31%via NVD
CVE-2024-55890MediumPoC
1y ago

D-Tale allows Remote Code Execution through the Custom Filter Input

D-Tale allows Remote Code Execution through the Custom Filter Input

▾ Twilightdtale · dtaleEPSS 2.4%via OSV
CVE-2024-55633Medium· 6.5
1y ago

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

▾ Sunlitapache-superset · apache-supersetEPSS 2.8%via OSV
CVE-2024-53949Medium· 6.5
1y ago

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

▾ Sunlitapache-superset · apache-supersetEPSS 0.72%via OSV

Most-affected vendors

By CVEs published in the period.