Weekly digest
Week 17, 2023 (24–30 Apr)
A busier-than-usual week with 17 new CVEs (recent average about 13). Severity skewed high: 5 critical and 10 high, 88% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. ui was the most-affected vendor with 6.
New this week, ranked by depth score
The 12 that matter most of the 17 published.
CVE-2023-27524High· 8.9CISA KEVPoCApache superset missing check for default SECRET_KEY
Apache superset missing check for default SECRET_KEY
CVE-2022-37454Critical· 9.8Buffer overflow in sponge queue functions
Buffer overflow in sponge queue functions
CVE-2023-22651Critical· 9.9Rancher Webhook is misconfigured during upgrade process
Rancher Webhook is misconfigured during upgrade process
CVE-2023-27973Critical· 9.8Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.
Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.
CVE-2023-27972Critical· 9.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.
CVE-2023-27971Critical· 9.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.
CVE-2023-2375High· 7.2PoCA weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is po…
CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS
Unrestricted file upload in kiwi TCMS
CVE-2023-2378High· 7.2A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes command injection. The attack may be…
CVE-2023-2377High· 7.2A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The at…
CVE-2023-2376High· 7.2A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads to command inject…
CVE-2023-2374High· 7.2A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Management Interface. Performing a manipulation of the argument ecn-down results in comman…
Most-affected vendors
By CVEs published in the period.