VulnSea

Weekly digest

Week 32, 2023 (7–13 Aug)

A busier-than-usual week with 14 new CVEs (recent average about 10). Severity skewed high: 9 high, 64% of the total. No new KEV entries.

14
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2023-39363High· 8.7
3y ago

Vyper has incorrectly allocated named re-entrancy locks

Vyper has incorrectly allocated named re-entrancy locks

▾ Twilightvyper · vyperEPSS 0.82%via OSV
CVE-2023-39349High· 8.1
3y ago

Privilege escalation via ApiTokensEndpoint

Privilege escalation via ApiTokensEndpoint

▾ Twilightsentry · sentryEPSS 1.1%via OSV
CVE-2023-39553High· 7.5
3y ago

apache-airflow-providers-apache-drill Improper Input Validation vulnerability

apache-airflow-providers-apache-drill Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-apache-drill · apache-airflow-providers-apache-drillEPSS 2.3%via OSV
CVE-2023-39533High· 7.5
3y ago

go-libp2p is the Go implementation of the libp2p Networking Stack

go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verifi…

▾ Twilightlibp2p · go-libp2pEPSS 1.5%via NVD
CVE-2020-35141High· 7.5
3y ago

FaucetSDN Ryu Denial of Service Vulnerability

FaucetSDN Ryu Denial of Service Vulnerability

▾ Twilightryu · ryuEPSS 0.95%via OSV
CVE-2020-35139High· 7.5
3y ago

FaucetSDN Ryu Denial of Service Vulnerability

FaucetSDN Ryu Denial of Service Vulnerability

▾ Twilightryu · ryuEPSS 0.95%via OSV
CVE-2023-4241High· 7.5
3y ago

lol-html panics on certain HTML inputs

lol-html panics on certain HTML inputs

▾ Twilightlol-html · lol-htmlEPSS 0.69%via OSV
CVE-2023-3518High· 7.4
3y ago

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

▾ Twilighthashicorp · github.com/hashicorp/consulEPSS 0.45%via OSV
CVE-2023-33953High· 7.5
3y ago

Excessive Iteration in gRPC

Excessive Iteration in gRPC

▾ Twilightgrpcio · grpcioEPSS 0.48%via OSV
CVE-2023-39523Medium· 6.8
3y ago

ScanCode.io command injection in docker image fetch process

ScanCode.io command injection in docker image fetch process

▾ Sunlitscancodeio · scancodeioEPSS 2.9%via OSV
CVE-2023-39965Medium· 6.5
3y ago

1Panel Arbitrary File Download vulnerability

1Panel Arbitrary File Download vulnerability

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 0.44%via OSV
CVE-2023-39531Medium· 6.5
3y ago

Sentry vulnerable to incorrect credential validation on OAuth token requests

Sentry vulnerable to incorrect credential validation on OAuth token requests

▾ Sunlitsentry · sentryEPSS 0.36%via OSV

Most-affected vendors

By CVEs published in the period.