VulnSea

Weekly digest

Week 27, 2023 (3–9 Jul)

A busier-than-usual week with 13 new CVEs (recent average about 10). Of those, 1 critical and 5 high. No new KEV entries. grpc was the most-affected vendor with 3.

13
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2023-36188Critical· 9.8
3y ago

langchain vulnerable to arbitrary code execution

langchain vulnerable to arbitrary code execution

▾ Midnightlangchain · langchainEPSS 1.9%via OSV
CVE-2023-36809High· 8.1
3y ago

Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox

Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox

▾ Twilightkiwitcms · kiwitcmsEPSS 0.69%via OSV
CVE-2023-36827High· 7.5
3y ago

ethyca-fides Webserver API Path Traversal vulnerability

ethyca-fides Webserver API Path Traversal vulnerability

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.5%via OSV
CVE-2023-1428High· 7.5
3y ago

gRPC Reachable Assertion issue

gRPC Reachable Assertion issue

▾ Twilightgrpc · io.grpc:grpc-protobufEPSS 0.41%via OSV
CVE-2023-36814High· 7.5
3y ago

Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module

Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module

▾ Twilightproducts-cmfcore · products-cmfcoreEPSS 0.72%via OSV
CVE-2023-32731High· 7.4
3y ago

Connection confusion in gRPC

Connection confusion in gRPC

▾ Twilightgrpc · io.grpc:grpc-protobufEPSS 0.50%via OSV
CVE-2023-36829Medium· 6.8
3y ago

Sentry CORS misconfiguration

Sentry CORS misconfiguration

▾ Sunlitsentry · sentryEPSS 0.67%via OSV
CVE-2023-30776Medium· 6.5
3y ago

Apache Superset vulnerable to Exposure of Sensitive Information

Apache Superset vulnerable to Exposure of Sensitive Information

▾ Sunlitapache-superset · apache-supersetEPSS 2.1%via OSV
CVE-2023-25504Medium· 6.5
3y ago

Apache Superset Server-Side Request Forgery vulnerability

Apache Superset Server-Side Request Forgery vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.96%via OSV
CVE-2023-36458Medium· 6.3
3y ago

1Panel vulnerable to command injection when entering the container terminal

1Panel vulnerable to command injection when entering the container terminal

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 2.3%via OSV
CVE-2023-35934Medium· 6.1
3y ago

yt-dlp File Downloader cookie leak

yt-dlp File Downloader cookie leak

▾ Sunlityt-dlp · yt-dlpEPSS 1.0%via OSV
CVE-2023-34457Medium· 5.9
3y ago

MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form

MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form

▾ Sunlitmechanicalsoup · mechanicalsoupEPSS 1.1%via OSV

Most-affected vendors

By CVEs published in the period.