Weekly digest
Week 16, 2023 (17–23 Apr)
14 new CVEs this week, in line with the recent average. No new KEV entries. Cisco was the most-affected vendor with 6.
New this week, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2023-30622Medium· 6.7A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation
A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation
CVE-2023-20090Medium· 6.7Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-2208Medium· 6.3A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0
A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file details.php. The manipulation of the argument id leads to sql …
CVE-2023-2207Medium· 6.3A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0
A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file contactus1.php. The manipulation of the argument email leads to sql injection. The…
CVE-2023-2206Medium· 6.3A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0
A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file contactus.php. The manipulation of the argument email leads to sql injection. It is poss…
CVE-2023-2205Medium· 6.3A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument email l…
CVE-2023-2204Medium· 6.3A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file faqs.php. The manipulation of the argument id leads …
CVE-2023-20091Medium· 5.1Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20094Medium· 4.3Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20093Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20092Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20004Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
Most-affected vendors
By CVEs published in the period.