Weekly digest
Week 8, 2023 (20–26 Feb)
A busier-than-usual week with 9 new CVEs (recent average about 8). Severity skewed high: 2 critical and 3 high, 56% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mayurik was the most-affected vendor with 3.
New this week, ranked by depth score
The 9 that matter most of the 9 published.
CVE-2022-48329Critical· 9.8MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
CVE-2022-48328Critical· 9.8app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
CVE-2023-25956High· 7.5Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information
Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information
CVE-2023-25692High· 7.5Apache Airflow Google Provider Improper Input Validation vulnerability
Apache Airflow Google Provider Improper Input Validation vulnerability
CVE-2023-25656High· 7.5notation-go has excessive memory allocation on verification
notation-go has excessive memory allocation on verification
CVE-2023-0943Medium· 4.7PoCA vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0
A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler.…
CVE-2023-0946Medium· 6.3A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical
A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The manipulation of the argument i…
CVE-2023-25823Medium· 5.4Update share links to use FRP instead of SSH tunneling
Update share links to use FRP instead of SSH tunneling
CVE-2023-0945Low· 3.5A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0
A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0. Affected is an unknown function of the file index.php?page=add-category. The manipulation of the argument Name with the inp…
Most-affected vendors
By CVEs published in the period.