NVD disclosure day

Published threat advisories for September 17, 2024

CVE advisoryCRITICAL

CVE-2024-44004

WPCargo Track & Trace SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the WPCargo Track & Trace WordPress plugin. This flaw could allow unauthenticated attackers to manipulate or access sensitive data by injecting malicious SQL commands over the network. Organizations should verify if this plugin is in use to assess potential exposure and

CVE advisoryCRITICAL

CVE-2024-38183

GroupMe Privilege Escalation Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper access control vulnerability in GroupMe, a public-facing messaging service, could allow an unauthenticated attacker to gain elevated privileges over a network, potentially impacting the confidentiality, integrity, and availability of the service. This issue is significant because it affects a widely used co

CVE advisoryKnown Exploit

CVE-2024-38812

VMware vCenter Server Network Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap-overflow vulnerability in VMware vCenter Server's DCERPC protocol implementation allows for remote code execution. This impacts organizations by enabling attackers with network access to potentially compromise systems, leading to data breaches or operational disruptions. The business risk is high due to the expl

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-7387

OpenShift Builder Command Injection and Privilege Escalation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in OpenShift's builder allows a privileged attacker to inject commands via path traversal, potentially leading to arbitrary command execution and elevated privileges on the host node. The vulnerability affects the builder container when using the "Docker" strategy and manipulating the `spec.source.secrets.secret

CVE advisoryCRITICAL

CVE-2024-45496

OpenShift Build Process Command Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in OpenShift's build process allows an attacker with developer access to execute arbitrary commands on a worker node by providing a crafted configuration file during code cloning. This can lead to escalated permissions on the node running the container, impacting the cluster. This vulnerability is relevant if in