Weekly digest
Week 30, 2023 (24–30 Jul)
12 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 5 high, 58% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. paddlepaddle was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 12 published.
CVE-2023-35078Critical· 9.8CISA KEV0dayPoCAn authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
CVE-2023-38673Critical· 9.6Command injection in PaddlePaddle
Command injection in PaddlePaddle
CVE-2023-3640High· 7.0PoCA possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-…
CVE-2023-38671High· 8.3Heap buffer overflow in PaddlePaddle
Heap buffer overflow in PaddlePaddle
CVE-2023-38669High· 8.3Use after free in PaddlePaddle
Use after free in PaddlePaddle
CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads
Improper authorization on debug and artifact file downloads
CVE-2023-37920High· 7.5Removal of e-Tugra root certificate
Removal of e-Tugra root certificate
CVE-2023-3637Medium· 6.5Denial of service in neutron
Denial of service in neutron
CVE-2023-3384Medium· 5.4A flaw was found in the Quay registry
A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an imag…
CVE-2023-38672Medium· 4.7Float point exception (FPE) in paddlepaddle
Float point exception (FPE) in paddlepaddle
CVE-2023-38670Medium· 4.7Null pointer dereference in PaddlePaddle
Null pointer dereference in PaddlePaddle
CVE-2023-37900Low· 3.4Denial of service from large image
Denial of service from large image
Most-affected vendors
By CVEs published in the period.