VulnSea

Weekly digest

Week 3, 2023 (16–22 Jan)

A busier-than-usual week with 13 new CVEs (recent average about 10). Of those, 1 critical and 2 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. apache-superset was the most-affected vendor with 7.

13
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2022-47966Critical· 9.8CISA KEVPoC
3y ago

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…

▾ Hadalzohocorp · manageengine_access_manager_plusEPSS 100%via NVD
CVE-2022-43719High· 8.8
3y ago

Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints

Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints

▾ Twilightapache-superset · apache-supersetEPSS 0.57%via OSV
CVE-2023-0433High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

▾ Twilightneovim · neovimEPSS 0.52%via NVD
CVE-2022-47950Medium· 6.5
3y ago

OpenStack Swift XML external entities (XXE) Injection

OpenStack Swift XML external entities (XXE) Injection

▾ Sunlitswift · swiftEPSS 1.0%via OSV
CVE-2023-24027Medium· 6.1
3y ago

In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

▾ Sunlitmisp-project · mispEPSS 0.40%via NVD
CVE-2023-22298Medium· 6.1
3y ago

pgAdmin 4 Open Redirect vulnerability

pgAdmin 4 Open Redirect vulnerability

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.92%via OSV
CVE-2023-0434Medium· 5.4
3y ago

Improper Input Validation in pyload-ng

Improper Input Validation in pyload-ng

▾ Sunlitpyload-ng · pyload-ngEPSS 0.82%via OSV
CVE-2022-43721Medium· 5.4
3y ago

Apache Superset Open Redirect vulnerability

Apache Superset Open Redirect vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2022-43720Medium· 5.4
3y ago

Apache Superset vulnerable to Injection

Apache Superset vulnerable to Injection

▾ Sunlitapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2022-43718Medium· 5.4
3y ago

Apache Superset is vulnerable to Cross-Site Scripting (XSS)

Apache Superset is vulnerable to Cross-Site Scripting (XSS)

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2022-43717Medium· 5.4
3y ago

Apache Superset vulnerable to Cross-site Scripting

Apache Superset vulnerable to Cross-site Scripting

▾ Sunlitapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2022-41703Medium· 5.4
3y ago

Apache Superset's SQL Alchemy connector vulnerable to SQL Injection

Apache Superset's SQL Alchemy connector vulnerable to SQL Injection

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV

Most-affected vendors

By CVEs published in the period.