Weekly digest
Week 51, 2024 (16–22 Dec)
A quiet week: only 6 new CVEs against a recent average of about 19. Severity skewed high: 1 critical and 2 high, 50% of the total. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-55956Critical· 9.8CISA KEVPoCIn Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
CVE-2024-35250High· 7.8CISA KEVPoCWindows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
New this week, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2024-56327Critical· 9.8pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
CVE-2024-21549High· 8.6Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method
Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which a…
CVE-2024-51532High· 7.1Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modificati…
CVE-2024-56142Medium· 6.5PGHoard Path Traversal vulnerability
PGHoard Path Traversal vulnerability
CVE-2024-10973Medium· 5.7A vulnerability was found in Keycloak
A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent n…
GHSA-32gq-x56h-299cMediumage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
Most-affected vendors
By CVEs published in the period.