Weekly digest
Week 28, 2023 (10–16 Jul)
7 new CVEs this week, in line with the recent average. Severity skewed high: 6 high, 86% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2023-37474High· 7.5PoCcopyparty vulnerable to path traversal attack
copyparty vulnerable to path traversal attack
CVE-2023-37415High· 8.8Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
CVE-2023-34236High· 8.5Weave GitOps Terraform Controller Information Disclosure Vulnerability
Weave GitOps Terraform Controller Information Disclosure Vulnerability
CVE-2023-37271High· 8.4RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
CVE-2023-38325High· 7.5cryptography mishandles SSH certificates
cryptography mishandles SSH certificates
CVE-2023-3617High· 7.3A vulnerability was found in SourceCodester Best POS Management System 1.0
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation of the argument userna…
GHSA-2w8w-qhg4-f78jMedium· 6.5A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries
A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries
Most-affected vendors
By CVEs published in the period.