VulnSea

Weekly digest

Week 50, 2022 (12–18 Dec)

8 new CVEs this week, in line with the recent average. Severity skewed high: 4 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Red Hat was the most-affected vendor with 3.

8
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2022-4223High· 8.8PoC
3y ago

pgadmin4 vulnerable to Code Injection

pgadmin4 vulnerable to Code Injection

▾ Midnightpgadmin4 · pgadmin4EPSS 80%via OSV
CVE-2022-23526High· 7.5⚖ disputed
3y ago

helm: Denial of service through schema file (CVE-2022-23526)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartut…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.86%via CSAF
CVE-2022-23525High· 7.5⚖ disputed
3y ago

helm: Denial of service through through repository index file (CVE-2022-23525)

A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index fil…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.14EPSS 0.86%via CSAF
CVE-2022-23524High· 7.5⚖ disputed
3y ago

helm: Denial of service through string value parsing (CVE-2022-23524)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…

▾ TwilightRed Hat · RHACS 4.0 for RHEL 8EPSS 0.78%via CSAF
CVE-2022-42343Medium· 6.5
3y ago

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the app…

▾ Sunlitadobe · campaignEPSS 1.4%via NVD
CVE-2022-4589Medium· 6.1
3y ago

Terms and Conditions Module vulnerable to Open Redirect

Terms and Conditions Module vulnerable to Open Redirect

▾ Sunlitdjango-termsandconditions · django-termsandconditionsEPSS 0.48%via OSV
CVE-2022-4312Medium· 5.5
3y ago

A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3

A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to disco…

▾ Sunlitarcinfo · pcvueEPSS 0.12%via NVD
CVE-2022-4311Medium· 4.7
3y ago

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConne…

▾ Sunlitarcinfo · pcvueEPSS 0.34%via NVD

Most-affected vendors

By CVEs published in the period.