Weekly digest
Week 46, 2022 (14–20 Nov)
A quiet week: only 3 new CVEs against a recent average of about 8. Of those, 1 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 3 that matter most of the 3 published.
CVE-2022-42118Medium· 6.1PoCA Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject…
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject…
CVE-2022-3920High· 7.5Missing Authorization in HashiCorp Consul
Missing Authorization in HashiCorp Consul
CVE-2022-20922Medium· 5.8Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial …
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial …
Most-affected vendors
By CVEs published in the period.