VulnSea

Weekly digest

Week 36, 2023 (4–10 Sep)

A heavy week: 27 new CVEs, well above the recent average of about 11. Of those, 8 high. 5 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. apache-superset was the most-affected vendor with 8.

27
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 27 published.

CVE-2023-28434High· 8.8CISA KEVPoC
3y ago

Privilege Escalation on Linux/MacOS

Privilege Escalation on Linux/MacOS

▾ Abyssalminio · github.com/minio/minioEPSS 7.9%via OSV
CVE-2023-39265Medium· 6.5PoC
3y ago

Apache Superset Improper Input Validation vulnerability

Apache Superset Improper Input Validation vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 86%via OSV
CVE-2023-20269Medium· 5.0CISA KEV
3y ago

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

▾ Midnightcisco · adaptive_security_appliance_softwareEPSS 25%via NVD
CVE-2023-4622High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

▾ Midnightlinux · linux_kernelEPSS 0.61%via NVD
CVE-2023-37941Medium· 6.6PoC
3y ago

Apache Superset Deserialization of Untrusted Data vulnerability

Apache Superset Deserialization of Untrusted Data vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 35%via OSV
CVE-2023-41319High· 8.8
3y ago

Remote Code Execution in Custom Integration Upload

Remote Code Execution in Custom Integration Upload

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.94%via OSV
CVE-2023-4244High· 7.8
3y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-4781High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

▾ Twilightneovim · neovimEPSS 0.61%via NVD
CVE-2023-4752High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4750High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

▾ Twilightneovim · neovimEPSS 0.53%via NVD
CVE-2023-4733High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

▾ Twilightneovim · neovimEPSS 0.54%via NVD
CVE-2023-41050Medium· 6.8
3y ago

Information disclosure in AccessControl

Information disclosure in AccessControl

▾ Sunlitaccesscontrol · accesscontrolEPSS 0.64%via OSV

Most-affected vendors

By CVEs published in the period.