VulnSea

Weekly digest

Week 4, 2023 (23–29 Jan)

8 new CVEs this week, in line with the recent average. Of those, 3 high. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

8
New CVEs
0
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2022-4510High· 7.8PoC
3y ago

Path traversal in binwalk

Path traversal in binwalk

▾ Midnightbinwalk · binwalkEPSS 22%via OSV
CVE-2023-22736High· 8.5
3y ago

Controller reconciles apps outside configured namespaces when sharding is enabled

Controller reconciles apps outside configured namespaces when sharding is enabled

▾ Twilightargoproj · github.com/argoproj/argo-cd/v2EPSS 0.78%via OSV
CVE-2023-0509High· 7.4
3y ago

Improper Certificate Validation in pyload-ng

Improper Certificate Validation in pyload-ng

▾ Twilightpyload-ng · pyload-ngEPSS 0.53%via OSV
CVE-2022-2712Medium· 6.5
3y ago

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to acces…

▾ Sunliteclipse · glassfishEPSS 0.94%via NVD
CVE-2023-24070Medium· 6.1
3y ago

app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2022-47951Medium· 5.7
3y ago

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

▾ Sunlitcinder · cinderEPSS 1.0%via OSV
CVE-2023-0488Medium· 5.4
3y ago

Cross-site Scripting in pyload-ng

Cross-site Scripting in pyload-ng

▾ Sunlitpyload-ng · pyload-ngEPSS 0.83%via OSV
CVE-2023-23608Medium· 5.4
3y ago

Path traversal in spotipy

Path traversal in spotipy

▾ Sunlitspotipy · spotipyEPSS 0.66%via OSV

Most-affected vendors

By CVEs published in the period.