VulnSea

Weekly digest

Week 9, 2023 (27 Feb – 5 Mar)

A heavy week: 14 new CVEs, well above the recent average of about 8. Of those, 5 high. No new KEV entries. vantage6 was the most-affected vendor with 3.

14
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2023-23929High· 8.8
3y ago

vantage6 refresh tokens do not expire

vantage6 refresh tokens do not expire

▾ Twilightvantage6 · vantage6EPSS 0.57%via OSV
CVE-2023-1118High· 7.8
3y ago

A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device

A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the…

▾ TwilightEPSS 0.28%via CVEORG
CVE-2023-0567High· 7.7
3y ago

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an applicatio…

▾ Twilightphp · phpEPSS 0.95%via NVD
CVE-2023-0594High· 7.3
3y ago

grafana: cross site scripting (CVE-2023-0594)

A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…

▾ TwilightRed Hat · Red Hat Ceph Storage 5.3 ToolsEPSS 9.2%via CSAF
CVE-2023-30797High· 7.5
3y ago

Lemur subject to insecure random generation

Lemur subject to insecure random generation

▾ Twilightlemur · lemurEPSS 0.79%via OSV
CVE-2023-1175Medium· 6.6
3y ago

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

▾ Sunlitneovim · neovimEPSS 0.45%via NVD
CVE-2023-26051Medium· 6.5
3y ago

Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions

Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions

▾ Sunlitsaleor · saleorEPSS 0.82%via OSV
CVE-2023-1170Medium· 6.6
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

▾ Sunlitneovim · neovimEPSS 0.50%via NVD
CVE-2023-22462Medium· 6.4
3y ago

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.6%via OSV
CVE-2023-22738Medium· 6.5
3y ago

vantage6 vulnerable to Improper Preservation of Permissions

vantage6 vulnerable to Improper Preservation of Permissions

▾ Sunlitvantage6 · vantage6EPSS 0.38%via OSV
CVE-2022-39228Medium· 6.5
3y ago

vantage6 vulnerable to Observable Response Discrepancy

vantage6 vulnerable to Observable Response Discrepancy

▾ Sunlitvantage6 · vantage6EPSS 0.60%via OSV
CVE-2023-26483Medium· 5.3
3y ago

gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb

gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb

▾ Sunlitrussellhaering · github.com/russellhaering/gosaml2EPSS 0.96%via OSV

Most-affected vendors

By CVEs published in the period.