VulnSea

Weekly digest

Week 2, 2023 (9–15 Jan)

10 new CVEs this week, in line with the recent average. Severity skewed high: 5 high, 50% of the total. No new KEV entries.

10
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2023-22491High· 8.1
3y ago

Gatsby is a free and open source framework based on React that helps developers build websites and apps

Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which…

▾ Twilightgatsbyjs · gatsby-transformer-remarkEPSS 0.61%via NVD
CVE-2023-0288High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

▾ Twilightneovim · neovimEPSS 0.48%via NVD
CVE-2022-4696High· 7.8
3y ago

There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation

There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, s…

▾ Twilightnetapp · h410s_firmwareEPSS 0.43%via NVD
CVE-2022-41721High· 7.5
3y ago

x/net/http2/h2c: request smuggling (CVE-2022-41721)

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…

▾ TwilightRed Hat · OpenShift Service Mesh 2.1EPSS 1.8%via CSAF
CVE-2022-4885High· 7.5
3y ago

sviehb/jefferson vulnerable to path traversal

sviehb/jefferson vulnerable to path traversal

▾ Twilightjefferson · jeffersonEPSS 0.75%via OSV
CVE-2023-0227Medium· 6.5
3y ago

Pyload Insufficient Session Expiration vulnerability

Pyload Insufficient Session Expiration vulnerability

▾ Sunlitpyload-ng · pyload-ngEPSS 0.66%via OSV
CVE-2023-22492Medium· 5.9
3y ago

Zitadel RefreshToken invalidation vulnerability

Zitadel RefreshToken invalidation vulnerability

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.60%via OSV
CVE-2022-2196Medium· 5.8
3y ago

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…

▾ Sunlitlinux · linux_kernelEPSS 0.29%via NVD
CVE-2023-20008Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …

▾ SunlitCisco · Cisco RoomOS SoftwareEPSS 0.19%via CSAF
CVE-2023-20002Medium· 4.4
3y ago

Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.16%via CSAF

Most-affected vendors

By CVEs published in the period.