VulnSea

Weekly digest

Week 16, 2023 (17–23 Apr)

14 new CVEs this week, in line with the recent average. No new KEV entries. Cisco was the most-affected vendor with 6.

14
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2023-30622Medium· 6.7
3y ago

A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation

A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation

▾ Sunlitclusternet · github.com/clusternet/clusternetEPSS 0.19%via OSV
CVE-2023-20090Medium· 6.7
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.21%via CSAF
CVE-2023-2208Medium· 6.3
3y ago

A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file details.php. The manipulation of the argument id leads to sql …

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-2207Medium· 6.3
3y ago

A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file contactus1.php. The manipulation of the argument email leads to sql injection. The…

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-2206Medium· 6.3
3y ago

A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file contactus.php. The manipulation of the argument email leads to sql injection. It is poss…

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.74%via NVD
CVE-2023-2205Medium· 6.3
3y ago

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument email l…

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-2204Medium· 6.3
3y ago

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file faqs.php. The manipulation of the argument id leads …

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-20091Medium· 5.1
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.19%via CSAF
CVE-2023-20094Medium· 4.3
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.27%via CSAF
CVE-2023-20093Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.19%via CSAF
CVE-2023-20092Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.19%via CSAF
CVE-2023-20004Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco RoomOS SoftwareEPSS 0.19%via CSAF

Most-affected vendors

By CVEs published in the period.