VulnSea

Weekly digest

Week 45, 2022 (7–13 Nov)

A quiet week: only 7 new CVEs against a recent average of about 15. Of those, 2 high. No new KEV entries.

7
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2022-39306High· 8.1
3y ago

grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)

An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.76%via CSAF
CVE-2022-21198High· 7.9
3y ago

Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

▾ Twilightintel · celeron_1000m_firmwareEPSS 0.15%via NVD
CVE-2022-44244Medium· 6.6
3y ago

Lin CMS vulnerable to Improper Authentication

Lin CMS vulnerable to Improper Authentication

▾ Sunlitlin-cms · lin-cmsEPSS 1.1%via OSV
CVE-2022-42966Medium· 5.9
3y ago

cleo is vulnerable to Regular Expression Denial of Service (ReDoS)

cleo is vulnerable to Regular Expression Denial of Service (ReDoS)

▾ Sunlitcleo · cleoEPSS 0.95%via OSV
CVE-2022-42965Medium· 5.9
3y ago

snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)

snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.86%via OSV
CVE-2022-42964Medium· 5.9
3y ago

pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)

pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)

▾ Sunlitpymatgen · pymatgenEPSS 0.86%via OSV
CVE-2022-39307Medium· 5.3
3y ago

grafana: User enumeration via forget password (CVE-2022-39307)

An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.75%via CSAF

Most-affected vendors

By CVEs published in the period.