Weekly digest
Week 34, 2023 (21–27 Aug)
A heavy week: 21 new CVEs, well above the recent average of about 11. Of those, 4 critical and 5 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. invisible-island was the most-affected vendor with 6.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2023-38831High· 7.8CISA KEV0dayPoCRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and al…
CVE-2022-48174Critical· 9.8There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
CVE-2023-39809Critical· 9.8N.V.K.INTER CO., LTD
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.
CVE-2023-39808Critical· 9.8N.V.K.INTER CO., LTD
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQ…
CVE-2023-39807Critical· 9.8N.V.K.INTER CO., LTD
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.
CVE-2023-4548Medium· 6.3PoCA vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3
A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql inje…
CVE-2023-32079High· 8.8Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
CVE-2023-4547Low· 3.5PoCA flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3
A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible…
CVE-2023-38976High· 7.5Weaviate denial of service vulnerability
Weaviate denial of service vulnerability
CVE-2023-39660Highpandasai vulnerable to prompt injection
pandasai vulnerable to prompt injection
CVE-2023-32078High· 7.5Netmaker IDOR Allows User to Update Other User's Password
Netmaker IDOR Allows User to Update Other User's Password
CVE-2020-19190Medium· 6.5Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Most-affected vendors
By CVEs published in the period.