VulnSea

Weekly digest

Week 23, 2023 (5–11 Jun)

10 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 7 high, 80% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. rancher was the most-affected vendor with 3.

10
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2023-33977High· 8.1PoC
3y ago

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

▾ Midnightkiwitcms · kiwitcmsEPSS 0.87%via OSV
CVE-2023-22647Critical· 9.9
3y ago

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2023-33733High· 7.8PoC
3y ago

Reportlab vulnerable to remote code execution

Reportlab vulnerable to remote code execution

▾ Midnightreportlab · reportlabEPSS 2.1%via OSV
CVE-2020-10676High· 8.8
3y ago

Rancher users retain access after moving namespaces into projects they don't have access to

Rancher users retain access after moving namespaces into projects they don't have access to

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.0%via OSV
CVE-2022-43760High· 8.4
3y ago

Rancher UI has multiple Cross-Site Scripting (XSS) issues

Rancher UI has multiple Cross-Site Scripting (XSS) issues

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2023-33967High· 8.2
3y ago

SQL injection when using MySQL/PostgreSQL data checking

SQL injection when using MySQL/PostgreSQL data checking

▾ Twilightmegaease · github.com/megaease/easeprobeEPSS 0.66%via OSV
CVE-2023-2801High· 7.5
3y ago

Grafana Missing Synchronization vulnerability

Grafana Missing Synchronization vulnerability

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.74%via OSV
CVE-2023-34239High· 7.3
3y ago

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

▾ Twilightgradio · gradioEPSS 0.65%via OSV
CVE-2023-34091Medium· 6.5
3y ago

Kyverno resource with a deletionTimestamp may allow policy circumvention

Kyverno resource with a deletionTimestamp may allow policy circumvention

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.50%via OSV
CVE-2023-32682Medium· 5.4
3y ago

Synapse has improper checks for deactivated users during login

Synapse has improper checks for deactivated users during login

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.75%via OSV

Most-affected vendors

By CVEs published in the period.