Weekly digest
Week 45, 2022 (7–13 Nov)
A quiet week: only 7 new CVEs against a recent average of about 15. Of those, 2 high. No new KEV entries.
New this week, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2022-39306High· 8.1grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)
An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…
CVE-2022-21198High· 7.9Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2022-44244Medium· 6.6Lin CMS vulnerable to Improper Authentication
Lin CMS vulnerable to Improper Authentication
CVE-2022-42966Medium· 5.9cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-42965Medium· 5.9snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-42964Medium· 5.9pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)
pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-39307Medium· 5.3grafana: User enumeration via forget password (CVE-2022-39307)
An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.
Most-affected vendors
By CVEs published in the period.