Weekly digest
Week 44, 2022 (31 Oct – 6 Nov)
A quiet week: only 4 new CVEs against a recent average of about 16. Severity skewed high: 1 critical and 1 high, 50% of the total. No new KEV entries.
4
New CVEs
1
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 4 that matter most of the 4 published.
CVE-2022-3023Critical· 9.8TiDB vulnerable to Use of Externally-Controlled Format String
TiDB vulnerable to Use of Externally-Controlled Format String
▾ Midnightpingcap · github.com/pingcap/tidbEPSS 0.61%via OSV
CVE-2022-33684High· 8.1Apache Pulsar Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack
Apache Pulsar Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attack
▾ Twilightpulsar-client · pulsar-clientEPSS 0.74%via OSV
CVE-2022-3616Medium· 5.4OctoRPKI crashes when max iterations is reached
OctoRPKI crashes when max iterations is reached
▾ Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.43%via OSV
CVE-2022-20969Medium· 4.8A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability i…
A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability i…
▾ SunlitEPSS 0.47%via NVD
Most-affected vendors
By CVEs published in the period.