2024年7月5日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2024-27710 Eskooly privilege escalation

  • CVSS 9.8
  • 管理者/root への権限昇格の可能性

新たな重大 Eskooly privilege escalation(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2024-27712 Eskooly privilege escalation

  • CVSS 9.8
  • 管理者/root への権限昇格の可能性

新たな重大 Eskooly privilege escalation(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2024-29319 Personal-management-system Personal Management System SSRF

  • CVSS 9.8

新たな重大 Personal-management-system Personal Management System SSRF(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2024-23997 CVSS 9.6

Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.

CVE-2024-23998 CVSS 9.6

goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.

CVE-2024-27709 CVSS 9.8

SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of...

CVE-2024-27710 CVSS 9.8

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authe...

CVE-2024-27712 CVSS 9.8

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User...

CVE-2024-29319 CVSS 9.8

Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file.

CVE-2024-37768 CVSS 9.1

14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.

CVE-2024-38346 CVSS 9.8

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hype...

CVE-2024-39028 CVSS 9.8

An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

CVE-2024-39864 CVSS 9.8

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled vi...

Critical 公開を見る

cvelogic Threat Intelligence