VulnSea

Weekly digest

Week 35, 2023 (28 Aug – 3 Sep)

13 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 10 high, 85% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. neovim was the most-affected vendor with 3.

13
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2023-41265Critical· 9.6CISA KEVPoC
3y ago

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…

▾ Hadalqlik · qlik_senseEPSS 88%via NVD
CVE-2023-41266High· 8.2CISA KEVPoC
3y ago

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

▾ Abyssalqlik · qlik_senseEPSS 85%via NVD
CVE-2023-4346High· 7.5CISA KEV
3y ago

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the device…

▾ Abyssalknx · connection_authorizationEPSS 1.3%via NVD
CVE-2023-27604High· 8.8
3y ago

Airflow Sqoop Provider RCE Vulnerability

Airflow Sqoop Provider RCE Vulnerability

▾ Twilightapache-airflow-providers-apache-sqoop · apache-airflow-providers-apache-sqoopEPSS 1.7%via OSV
CVE-2023-4751High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4738High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

▾ Twilightneovim · neovimEPSS 0.60%via NVD
CVE-2023-4736High· 7.8
3y ago

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

▾ Twilightvim · vimEPSS 0.51%via NVD
CVE-2023-4735High· 7.8
3y ago

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

▾ Twilightvim · vimEPSS 0.60%via NVD
CVE-2023-4734High· 7.8
3y ago

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

▾ Twilightneovim · neovimEPSS 0.58%via NVD
CVE-2023-40590High· 7.8
3y ago

GitPython untrusted search path on Windows systems leading to arbitrary code execution

GitPython untrusted search path on Windows systems leading to arbitrary code execution

▾ Twilightgitpython · gitpythonEPSS 0.51%via OSV
CVE-2023-4611High· 7.0
3y ago

A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel

A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lea…

▾ Twilightlinux · linux_kernelEPSS 0.27%via NVD
CVE-2023-39968Medium· 6.1
3y ago

Open Redirect Vulnerability in jupyter-server

Open Redirect Vulnerability in jupyter-server

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.68%via OSV

Most-affected vendors

By CVEs published in the period.