VulnSea

Weekly digest

Week 25, 2023 (19–25 Jun)

10 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 4 high, 70% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mozilla was the most-affected vendor with 3.

10
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2023-3128Critical· 9.4PoC
3y ago

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana vulnerable to Authentication Bypass by Spoofing

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 4.0%via OSV
CVE-2023-36664High· 7.8PoC
3y ago

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

▾ Midnightartifex · ghostscriptEPSS 4.0%via NVD
GHSA-hj8m-9fhf-v7jpCritical· 10.0
3y ago

fief-server Server-Side Template Injection vulnerability

fief-server Server-Side Template Injection vulnerability

▾ Midnightfief-server · fief-servervia OSV
CVE-2023-29534Critical· 9.1
3y ago

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other ve…

▾ Midnightmozilla · firefox_focusEPSS 0.71%via NVD
CVE-2023-34758High· 8.1
3y ago

Silver vulnerable to MitM attack against implants due to a cryptography vulnerability

Silver vulnerable to MitM attack against implants due to a cryptography vulnerability

▾ Twilightbishopfox · github.com/bishopfox/sliverEPSS 0.59%via OSV
CVE-2023-25747High· 7.5
3y ago

A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android

A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affe…

▾ Twilightmozilla · firefox_mobileEPSS 0.60%via NVD
CVE-2023-35932High· 7.1
3y ago

jcvi vulnerable to Configuration Injection due to unsanitized user input

jcvi vulnerable to Configuration Injection due to unsanitized user input

▾ Twilightjcvi · jcviEPSS 1.9%via OSV
CVE-2023-29546Medium· 6.5
3y ago

When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information

When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are…

▾ Sunlitmozilla · firefox_focusEPSS 0.49%via NVD
CVE-2023-25499Medium· 5.7
3y ago

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1…

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1…

▾ Sunlitvaadin · vaadinEPSS 0.58%via NVD
CVE-2023-25500Low· 3.5
3y ago

Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names …

Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names …

▾ Sunlitvaadin · vaadinEPSS 0.51%via NVD

Most-affected vendors

By CVEs published in the period.