Weekly digest
Week 3, 2023 (16–22 Jan)
A busier-than-usual week with 13 new CVEs (recent average about 10). Of those, 1 critical and 2 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. apache-superset was the most-affected vendor with 7.
New this week, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2022-47966Critical· 9.8CISA KEVPoCMultiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
CVE-2022-43719High· 8.8Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
CVE-2023-0433High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
CVE-2022-47950Medium· 6.5OpenStack Swift XML external entities (XXE) Injection
OpenStack Swift XML external entities (XXE) Injection
CVE-2023-24027Medium· 6.1In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2023-22298Medium· 6.1pgAdmin 4 Open Redirect vulnerability
pgAdmin 4 Open Redirect vulnerability
CVE-2023-0434Medium· 5.4Improper Input Validation in pyload-ng
Improper Input Validation in pyload-ng
CVE-2022-43721Medium· 5.4Apache Superset Open Redirect vulnerability
Apache Superset Open Redirect vulnerability
CVE-2022-43720Medium· 5.4Apache Superset vulnerable to Injection
Apache Superset vulnerable to Injection
CVE-2022-43718Medium· 5.4Apache Superset is vulnerable to Cross-Site Scripting (XSS)
Apache Superset is vulnerable to Cross-Site Scripting (XSS)
CVE-2022-43717Medium· 5.4Apache Superset vulnerable to Cross-site Scripting
Apache Superset vulnerable to Cross-site Scripting
CVE-2022-41703Medium· 5.4Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
Most-affected vendors
By CVEs published in the period.