VulnSea

Weekly digest

Week 8, 2023 (20–26 Feb)

A busier-than-usual week with 9 new CVEs (recent average about 8). Severity skewed high: 2 critical and 3 high, 56% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mayurik was the most-affected vendor with 3.

9
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 9 that matter most of the 9 published.

CVE-2022-48329Critical· 9.8
3y ago

MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

▾ Midnightmisp-project · mispEPSS 0.94%via NVD
CVE-2022-48328Critical· 9.8
3y ago

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

▾ Midnightmisp-project · mispEPSS 1.3%via NVD
CVE-2023-25956High· 7.5
3y ago

Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information

Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information

▾ Twilightapache-airflow-providers-amazon · apache-airflow-providers-amazonEPSS 1.5%via OSV
CVE-2023-25692High· 7.5
3y ago

Apache Airflow Google Provider Improper Input Validation vulnerability

Apache Airflow Google Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-google · apache-airflow-providers-googleEPSS 1.8%via OSV
CVE-2023-25656High· 7.5
3y ago

notation-go has excessive memory allocation on verification

notation-go has excessive memory allocation on verification

▾ Twilightnotaryproject · github.com/notaryproject/notation-goEPSS 0.44%via OSV
CVE-2023-0943Medium· 4.7PoC
3y ago

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler.…

▾ Twilightmayurik · best_pos_management_systemEPSS 2.3%via NVD
CVE-2023-0946Medium· 6.3
3y ago

A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical

A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The manipulation of the argument i…

▾ Sunlitmayurik · best_pos_management_systemEPSS 0.49%via NVD
CVE-2023-25823Medium· 5.4
3y ago

Update share links to use FRP instead of SSH tunneling

Update share links to use FRP instead of SSH tunneling

▾ Sunlitgradio · gradioEPSS 0.55%via OSV
CVE-2023-0945Low· 3.5
3y ago

A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0

A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0. Affected is an unknown function of the file index.php?page=add-category. The manipulation of the argument Name with the inp…

▾ Sunlitmayurik · best_pos_management_systemEPSS 0.36%via NVD

Most-affected vendors

By CVEs published in the period.