VulnSea

Weekly digest

Week 17, 2023 (24–30 Apr)

A busier-than-usual week with 17 new CVEs (recent average about 13). Severity skewed high: 5 critical and 10 high, 88% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. ui was the most-affected vendor with 6.

17
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2023-27524High· 8.9CISA KEVPoC
3y ago

Apache superset missing check for default SECRET_KEY

Apache superset missing check for default SECRET_KEY

▾ Abyssalapache-superset · apache-supersetEPSS 97%via OSV
CVE-2022-37454Critical· 9.8
3y ago

Buffer overflow in sponge queue functions

Buffer overflow in sponge queue functions

▾ Midnightpysha3 · pysha3EPSS 5.8%via OSV
CVE-2023-22651Critical· 9.9
3y ago

Rancher Webhook is misconfigured during upgrade process

Rancher Webhook is misconfigured during upgrade process

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.78%via OSV
CVE-2023-27973Critical· 9.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

▾ Midnighthp · laserjet_pro_m304-m305_w1a46a_firmwareEPSS 1.5%via NVD
CVE-2023-27972Critical· 9.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.

▾ Midnighthp · laserjet_pro_m304-m305_w1a46a_firmwareEPSS 1.5%via NVD
CVE-2023-27971Critical· 9.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.

▾ Midnighthp · laserjet_pro_m304-m305_w1a46a_firmwareEPSS 0.90%via NVD
CVE-2023-2375High· 7.2PoC
3y ago

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is po…

▾ Midnightui · er-x_firmwareEPSS 9.3%via NVD
CVE-2023-30613High· 7.7
3y ago

Unrestricted file upload in kiwi TCMS

Unrestricted file upload in kiwi TCMS

▾ Twilightkiwitcms · kiwitcmsEPSS 1.0%via OSV
CVE-2023-2378High· 7.2
3y ago

A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes command injection. The attack may be…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2377High· 7.2
3y ago

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The at…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2376High· 7.2
3y ago

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads to command inject…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2374High· 7.2
3y ago

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Management Interface. Performing a manipulation of the argument ecn-down results in comman…

▾ Twilightui · er-x_firmwareEPSS 6.9%via NVD

Most-affected vendors

By CVEs published in the period.