VulnSea

Weekly digest

Week 21, 2023 (22–28 May)

8 new CVEs this week, in line with the recent average. Of those, 1 critical and 1 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

8
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2023-32321Critical· 9.8
3y ago

Ckan remote code execution and private information access via crafted resource ids

Ckan remote code execution and private information access via crafted resource ids

▾ Midnightckan · ckanEPSS 1.7%via OSV
CVE-2023-32681Medium· 6.1PoC
3y ago

Unintended leak of Proxy-Authorization header in requests

Unintended leak of Proxy-Authorization header in requests

▾ Twilightrequests · requestsEPSS 3.0%via OSV
CVE-2023-32698High· 7.1
3y ago

nfpm has incorrect default permissions

nfpm has incorrect default permissions

▾ Twilightgoreleaser · github.com/goreleaser/nfpm/v2EPSS 0.38%via OSV
CVE-2021-25748Medium· 6.5
3y ago

Ingress-nginx `path` sanitization can be bypassed with newline character

Ingress-nginx `path` sanitization can be bypassed with newline character

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.69%via OSV
CVE-2023-32686Medium· 5.4
3y ago

kiwitcms vulnerable to stored XSS via unrestricted files upload

kiwitcms vulnerable to stored XSS via unrestricted files upload

▾ Sunlitkiwitcms · kiwitcmsEPSS 0.43%via OSV
CVE-2023-30851Medium· 5.3
3y ago

Potential HTTP policy bypass when using header rules in Cilium

Potential HTTP policy bypass when using header rules in Cilium

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.66%via OSV
CVE-2023-33191Medium· 4.6
3y ago

kyverno seccomp control can be circumvented

kyverno seccomp control can be circumvented

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.48%via OSV
CVE-2023-33185Medium· 4.6
3y ago

Incorrect signature verification in django-ses

Incorrect signature verification in django-ses

▾ Sunlitdjango-ses · django-sesEPSS 0.23%via OSV

Most-affected vendors

By CVEs published in the period.