Weekly digest
Week 20, 2023 (15–21 May)
A quiet week: only 4 new CVEs against a recent average of about 13. Severity skewed high: 2 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
4
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 4 that matter most of the 4 published.
CVE-2023-32309High· 7.5PoCAny file can be included with the pymdown-snippets extension
Any file can be included with the pymdown-snippets extension
▾ Midnightpymdown-extensions · pymdown-extensionsEPSS 1.7%via OSV
CVE-2023-32758High· 7.5git-url-parse Regular Expression Denial of Service
git-url-parse Regular Expression Denial of Service
▾ Twilightgit-url-parse · git-url-parseEPSS 1.0%via OSV
CVE-2023-28045Medium· 6.3Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability
Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.
▾ Sunlitdell · aiops_collectorEPSS 0.18%via NVD
CVE-2023-29159Low· 3.7Starlette has Path Traversal vulnerability in StaticFiles
Starlette has Path Traversal vulnerability in StaticFiles
▾ Sunlitstarlette · starletteEPSS 2.0%via OSV
Most-affected vendors
By CVEs published in the period.