Weekly digest
Week 4, 2023 (23–29 Jan)
8 new CVEs this week, in line with the recent average. Of those, 3 high. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2022-47966Critical· 9.8CISA KEVPoCMultiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
CVE-2017-11357Critical· 9.8CISA KEVPoCProgress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2022-4510High· 7.8PoCPath traversal in binwalk
Path traversal in binwalk
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2023-0509High· 7.4Improper Certificate Validation in pyload-ng
Improper Certificate Validation in pyload-ng
CVE-2022-2712Medium· 6.5In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'
In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to acces…
CVE-2023-24070Medium· 6.1app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
CVE-2023-0488Medium· 5.4Cross-site Scripting in pyload-ng
Cross-site Scripting in pyload-ng
CVE-2023-23608Medium· 5.4Path traversal in spotipy
Path traversal in spotipy
Most-affected vendors
By CVEs published in the period.