Weekly digest
Week 52, 2022 (26 Dec – 1 Jan)
6 new CVEs this week, in line with the recent average. No new KEV entries. graphite-web was the most-affected vendor with 3.
6
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2021-4287Medium· 6.5binwalk vulnerable to UNIX Symbolic Link (Symlink) Following
binwalk vulnerable to UNIX Symbolic Link (Symlink) Following
▾ Sunlitbinwalk · binwalkEPSS 1.9%via OSV
CVE-2022-4730Medium· 5.4Graphite Web Cross-site Scripting vulnerability
Graphite Web Cross-site Scripting vulnerability
▾ Sunlitgraphite-web · graphite-webEPSS 0.77%via OSV
CVE-2022-4729Medium· 5.4Graphite Web Cross-site Scripting vulnerability
Graphite Web Cross-site Scripting vulnerability
▾ Sunlitgraphite-web · graphite-webEPSS 0.74%via OSV
CVE-2022-4728Medium· 5.4Graphite Web Cross-site Scripting vulnerability
Graphite Web Cross-site Scripting vulnerability
▾ Sunlitgraphite-web · graphite-webEPSS 0.77%via OSV
CVE-2019-25091Medium· 5.3nsupdate.info has Sensitive Cookie Without 'HttpOnly' Flag
nsupdate.info has Sensitive Cookie Without 'HttpOnly' Flag
▾ Sunlitnsupdate · nsupdateEPSS 0.62%via OSV
CVE-2022-2582Medium· 4.3AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
▾ Sunlitaws · github.com/aws/aws-sdk-goEPSS 0.48%via OSV
Most-affected vendors
By CVEs published in the period.