VulnSea

Weekly digest

Week 19, 2023 (8–14 May)

8 new CVEs this week, in line with the recent average. Severity skewed high: 4 high, 50% of the total. CISA added one CVE to the Known Exploited Vulnerabilities catalog. vyper was the most-affected vendor with 3.

8
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2023-2610High· 7.8
3y ago

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.

▾ Twilightvim · vimEPSS 0.46%via NVD
CVE-2023-32059High· 7.5
3y ago

Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls

Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls

▾ Twilightvyper · vyperEPSS 0.73%via OSV
CVE-2023-32058High· 7.5
3y ago

Vyper vulnerable to integer overflow in loop

Vyper vulnerable to integer overflow in loop

▾ Twilightvyper · vyperEPSS 0.91%via OSV
CVE-2023-31146High· 7.5
3y ago

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

▾ Twilightvyper · vyperEPSS 1.2%via OSV
CVE-2023-25309Medium· 6.1
3y ago

Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.

Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.

▾ Sunlitfetlife · rollout-uiEPSS 0.52%via NVD
CVE-2023-2609Medium· 5.5
3y ago

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.

▾ Sunlitvim · vimEPSS 0.47%via NVD
CVE-2023-1732Medium· 5.3
3y ago

Improper random reading in CIRCL

Improper random reading in CIRCL

▾ Sunlitcloudflare · github.com/cloudflare/circlEPSS 0.39%via OSV
CVE-2023-32082Low· 3.1
3y ago

etcd Key name can be accessed via LeaseTimeToLive API

etcd Key name can be accessed via LeaseTimeToLive API

▾ Sunlitetcd-io · github.com/etcd-io/etcdEPSS 0.74%via OSV

Most-affected vendors

By CVEs published in the period.