VulnSea

Weekly digest

Week 29, 2023 (17–23 Jul)

10 new CVEs this week, in line with the recent average. Of those, 2 critical and 2 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

10
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2023-3519Critical· 9.8CISA KEV0dayPoC
3y ago

Unauthenticated remote code execution

Unauthenticated remote code execution

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2023-3609High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…

▾ Midnightlinux · linux_kernelEPSS 0.45%via NVD
CVE-2023-37917Critical· 9.1
3y ago

KubePi Privilege Escalation vulnerability

KubePi Privilege Escalation vulnerability

▾ MidnightKubeOperator · github.com/KubeOperator/kubepiEPSS 0.74%via OSV
CVE-2023-37276Medium· 5.3PoC
3y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default…

▾ Twilightaiohttp · aiohttpEPSS 1.3%via NVD
CVE-2023-37788High· 7.5
3y ago

goproxy Denial of Service vulnerability

goproxy Denial of Service vulnerability

▾ Twilightelazarl · github.com/elazarl/goproxyEPSS 0.98%via OSV
CVE-2023-37918Medium· 6.8
3y ago

Dapr API token authentication bypass in HTTP endpoints

Dapr API token authentication bypass in HTTP endpoints

▾ Sunlitdapr · github.com/dapr/daprEPSS 1.4%via OSV
CVE-2023-37916Medium· 6.5
3y ago

KubePi may leak password hash of any user

KubePi may leak password hash of any user

▾ SunlitKubeOperator · github.com/KubeOperator/kubepiEPSS 0.81%via OSV
CVE-2023-22039Medium· 5.4
3y ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP …

▾ Sunlitoracle · agile_product_lifecycle_managementEPSS 0.36%via NVD
CVE-2023-37481Low· 2.7
3y ago

Fides Webserver Vulnerable to SVG Bomb File Uploads

Fides Webserver Vulnerable to SVG Bomb File Uploads

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.70%via OSV
CVE-2023-37480Low· 2.7
3y ago

Fides Webserver Vulnerable to Zip Bomb File Uploads

Fides Webserver Vulnerable to Zip Bomb File Uploads

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.69%via OSV

Most-affected vendors

By CVEs published in the period.