VulnSea

Weekly digest

Week 51, 2024 (16–22 Dec)

A quiet week: only 6 new CVEs against a recent average of about 19. Severity skewed high: 1 critical and 2 high, 50% of the total. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

6
New CVEs
1
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2024-56327Critical· 9.8
1y ago

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

▾ Midnightpyrage · pyrageEPSS 0.50%via OSV
CVE-2024-21549High· 8.6
1y ago

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which a…

▾ TwilightEPSS 0.61%via NVD
CVE-2024-51532High· 7.1
1y ago

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modificati…

▾ Twilightdell · powerstoreosEPSS 0.27%via NVD
CVE-2024-56142Medium· 6.5
1y ago

PGHoard Path Traversal vulnerability

PGHoard Path Traversal vulnerability

▾ Sunlitpghoard · pghoardEPSS 0.41%via OSV
CVE-2024-10973Medium· 5.7
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent n…

▾ SunlitEPSS 0.27%via NVD
GHSA-32gq-x56h-299cMedium
1y ago

age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

▾ Sunlitage · filippo.io/agevia OSV

Most-affected vendors

By CVEs published in the period.