VulnSea

Weekly digest

Week 11, 2023 (13–19 Mar)

8 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 1 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

8
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2023-28461Critical· 9.8CISA KEV
3y ago

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could…

▾ Hadalarraynetworks · arrayos_agEPSS 68%via NVD
CVE-2023-28531Critical· 9.8
3y ago

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

▾ Midnightopenbsd · opensshEPSS 2.3%via NVD
CVE-2023-27582Critical· 9.1
3y ago

Full authentication bypass if SASL authorization username is specified

Full authentication bypass if SASL authorization username is specified

▾ Midnightfoxcpp · github.com/foxcpp/maddyEPSS 1.0%via OSV
CVE-2023-1390High· 7.5
3y ago

A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module

A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packe…

▾ TwilightEPSS 5.1%via CVEORG
CVE-2023-28607Medium· 6.1
3y ago

js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

▾ Sunlitmisp-project · mispEPSS 0.38%via NVD
CVE-2023-28606Medium· 6.1
3y ago

js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

▾ Sunlitmisp-project · mispEPSS 0.38%via NVD
CVE-2021-29456Medium· 5.4
3y ago

Authelia allows open redirects on the logout endpoint

Authelia allows open redirects on the logout endpoint

▾ Sunlitauthelia · github.com/authelia/authelia/v4EPSS 0.51%via OSV
CVE-2023-27593Medium· 4.4
3y ago

cilium-agent container can access the host via `hostPath` mount

cilium-agent container can access the host via `hostPath` mount

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.22%via OSV

Most-affected vendors

By CVEs published in the period.