Weekly digest
Week 38, 2023 (18–24 Sep)
15 new CVEs this week, in line with the recent average. Of those, 5 high. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. schollz was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2017-6884High· 8.8CISA KEVPoCA command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numer…
CVE-2023-28434High· 8.8CISA KEVPoCPrivilege Escalation on Linux/MacOS
Privilege Escalation on Linux/MacOS
New this week, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2023-4853High· 8.1A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass …
CVE-2023-43620High· 7.8Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device
Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device
CVE-2023-43669High· 7.5Tungstenite allows remote attackers to cause a denial of service
Tungstenite allows remote attackers to cause a denial of service
CVE-2023-1625High· 7.4OpenStack Heat information leak vulnerability
OpenStack Heat information leak vulnerability
CVE-2023-42439High· 7.5GeoNode vulnerable to SSRF Bypass to return internal host data
GeoNode vulnerable to SSRF Bypass to return internal host data
CVE-2023-1633Medium· 6.6OpenStack Barbican credential leak flaw
OpenStack Barbican credential leak flaw
CVE-2023-1636Medium· 6.0OpenStack Barbican information disclosure vulnerability
OpenStack Barbican information disclosure vulnerability
CVE-2023-5002Medium· 6.0pgAdmin failed to properly control the server code
pgAdmin failed to properly control the server code
CVE-2023-4806Medium· 5.9A flaw has been identified in glibc
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the …
CVE-2023-43618Medium· 5.3Croc requires senders to provide local IP addresses in cleartext
Croc requires senders to provide local IP addresses in cleartext
CVE-2023-42441Medium· 5.3Vyper has incorrect re-entrancy lock when key is empty string
Vyper has incorrect re-entrancy lock when key is empty string
CVE-2023-43621Medium· 4.7Croc may expose secret to local users
Croc may expose secret to local users
Most-affected vendors
By CVEs published in the period.