CVE-2024-21182
Oracle WebLogic Server contains an unspecified vulnerability that is currently being exploited in the wild.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's brief is led by three critical WordPress component vulnerabilities, all rated CVSS 9.8, affecting the Seotheme, Background Image Cropper, and Travelscape products. The day brought 3 critical CVEs, up from none the prior day, alongside 33 high-priority issues, a 43% increase over yesterday's 23. CVE-2023-54352 in WordPress Seotheme, CVE-2024-58348 in Background Image Cropper, and CVE-2024-58349 in the Travelscape theme each enable high-impact compromise of affected sites. The disclosures cluster around web application and CMS components, with active exploitation observed across a broader set of products including Oracle WebLogic Server, the Linux kernel, the Android Framework, Magento, and SolarWinds Serv-U. No vendor patches were available at disclosure for the day's CVEs, so defenders should prioritize mitigations and monitoring while fixes are pending.
Immediate action: Prioritize WordPress installations running the Seotheme, Background Image Cropper, or Travelscape components, and review exposure to actively exploited products including Oracle WebLogic Server, SolarWinds Serv-U, and Magento. With no patches available for the day's critical CVEs, apply available mitigations, restrict access to affected components, and increase monitoring until vendor fixes are released.
Oracle WebLogic Server contains an unspecified vulnerability that is currently being exploited in the wild.
A privilege escalation vulnerability in the Linux Kernel cgroup_release_agent_write function allows unprivileged users to escape container environments and gain elevated host privileges.
An integer overflow vulnerability in the Android Framework allows for potential unauthorized system access and is currently tracked in the CISA KEV catalog.
Mirasvit Full Page Cache Warmer for Magento 2 contains a PHP object injection vulnerability allowing unauthenticated RCE via the CacheWarmer cookie.
SolarWinds Serv-U is vulnerable to an uncontrolled resource consumption flaw allowing unauthenticated attackers to crash the service via specially crafted POST requests.
WordPress Seotheme contains a critical remote code execution vulnerability allowing unauthenticated attackers to upload and execute arbitrary PHP files.
WordPress Background Image Cropper 1.2 allows unauthenticated attackers to execute arbitrary code via an insecure file upload endpoint.
WordPress Theme Travelscape 1.0.3 is susceptible to remote code execution due to insufficient validation of file uploads in the theme directory.
The WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector, allowing unauthenticated file uploads.
A use-after-free vulnerability in the WebShare component of Google Chrome on Android allows for potential remote code execution.
A use-after-free vulnerability in the Serial component of Google Chrome on Android allows for potential remote code execution.
A use-after-free vulnerability exists in the WebView component of Google Chrome for Android, potentially allowing for memory corruption or arbitrary code execution.
An integer overflow vulnerability in the V8 JavaScript engine of Google Chrome may lead to memory corruption or arbitrary code execution.
An inappropriate implementation flaw in the Google Chrome Installer for Windows may allow for unauthorized system-level actions.
WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting (XSS) vulnerability in the comment functionality.
Chanjet CRM 1.0 contains an SQL injection vulnerability in the /tools/jxf_dump_systable.php file due to improper sanitization of the 'gblOrgID' parameter.
An improper authorization vulnerability in BeikeShop up to 1.6.0.22 allows attackers to bypass security controls via the Stripe plugin callback.
An unrestricted file upload vulnerability in the Kushan2k student-management-system registration endpoint allows attackers to upload malicious files via the 'stimg' argument.
A security vulnerability has been identified in the code-projects Simple Flight Ticket Booking System.
A SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows remote attackers to compromise the database via the 'Password' argument in index2.php.
A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System.
A security vulnerability has been identified within the code-projects Online Music Site application.
A security vulnerability exists within the firewall driver component of Comodo Internet Security.
A vulnerability has been identified in the clash-verge-service-ipc package before version 2.
A security flaw has been identified in an unspecified product, requiring immediate investigation and remediation.
A security flaw has been identified in an unspecified product, necessitating immediate review and update procedures.
A security flaw has been identified in an unspecified component of Infor products.
A security vulnerability has been identified in the Jinher OA software, potentially exposing the system to unauthorized access or operational disruption.
A Server-Side Request Forgery (SSRF) vulnerability in perfree go-fastdfs-web allows unauthenticated attackers to perform unauthorized requests to internal systems via the /install/checkServer endpoint.
A security vulnerability has been detected in GL software, requiring further investigation to determine the specific impact and affected components.
A security flaw has been identified in GL software, requiring administrators to monitor vendor updates for mitigation instructions.
A vulnerability has been discovered in GL software, with further details pending from the vendor.
A security flaw in erzhongxmu JeeWMS enables remote information disclosure via the /base-boot/actuator component.
A flaw in Boost Serialization allows remote attackers to manipulate input data types due to improper validation during the serialization process.
A type confusion vulnerability in the Shared Pointer Handler component of USCiLab Cereal allows remote attackers to trigger unauthorized actions without user interaction.
A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System, which could lead to unauthorized system impacts.
A security flaw has been identified in the SourceCodester Class and Exam Timetabling System, potentially allowing unauthorized system access.
A security weakness has been identified in the SourceCodester Class and Exam Timetabling System, potentially impacting system security.
A security vulnerability has been detected in the SourceCodester Class and Exam Timetabling System, which could lead to unauthorized system interactions.
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 via the 'sy' argument in the /archive1.php file.
An SQL injection vulnerability in code-projects Online Music Site 1.0 allows attackers to manipulate the 'Category' argument in /Frontend/Search.php.