Weekly digest
Week 29, 2023 (17–23 Jul)
10 new CVEs this week, in line with the recent average. Of those, 2 critical and 2 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-3519Critical· 9.8CISA KEV0dayPoCUnauthenticated remote code execution
Unauthenticated remote code execution
CVE-2023-3609High· 7.8PoCA use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…
A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…
CVE-2023-37917Critical· 9.1KubePi Privilege Escalation vulnerability
KubePi Privilege Escalation vulnerability
CVE-2023-37276Medium· 5.3PoCaiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default…
CVE-2023-37788High· 7.5goproxy Denial of Service vulnerability
goproxy Denial of Service vulnerability
CVE-2023-37918Medium· 6.8Dapr API token authentication bypass in HTTP endpoints
Dapr API token authentication bypass in HTTP endpoints
CVE-2023-37916Medium· 6.5KubePi may leak password hash of any user
KubePi may leak password hash of any user
CVE-2023-22039Medium· 5.4Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient)
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP …
CVE-2023-37481Low· 2.7Fides Webserver Vulnerable to SVG Bomb File Uploads
Fides Webserver Vulnerable to SVG Bomb File Uploads
CVE-2023-37480Low· 2.7Fides Webserver Vulnerable to Zip Bomb File Uploads
Fides Webserver Vulnerable to Zip Bomb File Uploads
Most-affected vendors
By CVEs published in the period.