This weekly blog post is from via our unique intelligence collection pipelines. We are your eyes and ears online, including the Dark Web.
There are thousands of vulnerability discussions each week. SOS Intelligence gathers a list of the most discussed Common Vulnerabilities and Exposures (CVE) online for the previous week.
We make every effort to ensure the accuracy of the data presented. As this is an automated process some errors may creep in.
If you are feeling generous please do make us aware of anything you spot, feel free to follow us on Twitter @sosintel and DM us. Thank you!
1. CVE-2024-21762
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
https://nvd.nist.gov/vuln/detail/CVE-2024-21762
2. CVE-2024-26163
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-26163
3. CVE-2024-26246
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-26246
4. CVE-2024-26167
Microsoft Edge for Android Spoofing Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-26167
5. CVE-2023-6875
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.
https://nvd.nist.gov/vuln/detail/CVE-2023-6875
6. CVE-2023-27997
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
https://nvd.nist.gov/vuln/detail/CVE-2023-27997
7. CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an ‘@’ character followed by a file path in an argument with the file’s contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
https://nvd.nist.gov/vuln/detail/CVE-2024-23897
8. CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-21413
9. CVE-2024-27199
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
https://nvd.nist.gov/vuln/detail/CVE-2024-27199
10. CVE-2023-29360
Microsoft Streaming Service Elevation of Privilege Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2023-29360