Weekly digest
Week 13, 2023 (27 Mar – 2 Apr)
A quiet week: only 6 new CVEs against a recent average of about 12. Severity skewed high: 3 high, 50% of the total. No new KEV entries.
New this week, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2023-27489High· 7.6Kiwi TCMS Stored Cross-site Scripting via SVG file
Kiwi TCMS Stored Cross-site Scripting via SVG file
CVE-2023-1380High· 7.1A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buf…
CVE-2023-30620High· 7.5mindsdb arbitrary file write when extracting a remotely retrieved Tarball
mindsdb arbitrary file write when extracting a remotely retrieved Tarball
CVE-2023-0241Medium· 6.5pgAdmin 4 vulnerable to directory traversal
pgAdmin 4 vulnerable to directory traversal
CVE-2023-25661Medium· 6.5TensorFlow Denial of Service vulnerability
TensorFlow Denial of Service vulnerability
CVE-2023-28884Medium· 6.1In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
Most-affected vendors
By CVEs published in the period.