Weekly digest
Week 27, 2023 (3–9 Jul)
A busier-than-usual week with 13 new CVEs (recent average about 10). Of those, 1 critical and 5 high. No new KEV entries. grpc was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2023-36188Critical· 9.8langchain vulnerable to arbitrary code execution
langchain vulnerable to arbitrary code execution
CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
CVE-2023-36827High· 7.5ethyca-fides Webserver API Path Traversal vulnerability
ethyca-fides Webserver API Path Traversal vulnerability
CVE-2023-1428High· 7.5gRPC Reachable Assertion issue
gRPC Reachable Assertion issue
CVE-2023-36814High· 7.5Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
CVE-2023-32731High· 7.4Connection confusion in gRPC
Connection confusion in gRPC
CVE-2023-36829Medium· 6.8Sentry CORS misconfiguration
Sentry CORS misconfiguration
CVE-2023-30776Medium· 6.5Apache Superset vulnerable to Exposure of Sensitive Information
Apache Superset vulnerable to Exposure of Sensitive Information
CVE-2023-25504Medium· 6.5Apache Superset Server-Side Request Forgery vulnerability
Apache Superset Server-Side Request Forgery vulnerability
CVE-2023-36458Medium· 6.31Panel vulnerable to command injection when entering the container terminal
1Panel vulnerable to command injection when entering the container terminal
CVE-2023-35934Medium· 6.1yt-dlp File Downloader cookie leak
yt-dlp File Downloader cookie leak
CVE-2023-34457Medium· 5.9MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
Most-affected vendors
By CVEs published in the period.