VulnSea

Weekly digest

Week 28, 2023 (10–16 Jul)

7 new CVEs this week, in line with the recent average. Severity skewed high: 6 high, 86% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

7
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2023-37474High· 7.5PoC
3y ago

copyparty vulnerable to path traversal attack

copyparty vulnerable to path traversal attack

▾ Midnightcopyparty · copypartyEPSS 45%via OSV
CVE-2023-37415High· 8.8
3y ago

Apache Airflow Apache Hive Provider Improper Input Validation vulnerability

Apache Airflow Apache Hive Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-apache-hive · apache-airflow-providers-apache-hiveEPSS 1.6%via OSV
CVE-2023-34236High· 8.5
3y ago

Weave GitOps Terraform Controller Information Disclosure Vulnerability

Weave GitOps Terraform Controller Information Disclosure Vulnerability

▾ Twilightweaveworks · github.com/weaveworks/tf-controllerEPSS 0.96%via OSV
CVE-2023-37271High· 8.4
3y ago

RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

▾ Twilightrestrictedpython · restrictedpythonEPSS 0.85%via OSV
CVE-2023-38325High· 7.5
3y ago

cryptography mishandles SSH certificates

cryptography mishandles SSH certificates

▾ Twilightcryptography · cryptographyEPSS 0.73%via OSV
CVE-2023-3617High· 7.3
3y ago

A vulnerability was found in SourceCodester Best POS Management System 1.0

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation of the argument userna…

▾ Twilightmayurik · best_pos_management_systemEPSS 0.82%via NVD
GHSA-2w8w-qhg4-f78jMedium· 6.5
3y ago

A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries

A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries

▾ Sunlitjaegertracing · github.com/jaegertracing/jaegervia OSV

Most-affected vendors

By CVEs published in the period.