VulnSea

Weekly digest

Week 38, 2023 (18–24 Sep)

15 new CVEs this week, in line with the recent average. Of those, 5 high. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. schollz was the most-affected vendor with 3.

15
New CVEs
0
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2023-4853High· 8.1
3y ago

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass …

▾ Twilightquarkus · quarkusEPSS 1.4%via NVD
CVE-2023-43620High· 7.8
3y ago

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device

▾ Twilightschollz · github.com/schollz/croc/v9EPSS 0.36%via OSV
CVE-2023-43669High· 7.5
3y ago

Tungstenite allows remote attackers to cause a denial of service

Tungstenite allows remote attackers to cause a denial of service

▾ Twilighttungstenite · tungsteniteEPSS 2.1%via OSV
CVE-2023-1625High· 7.4
3y ago

OpenStack Heat information leak vulnerability

OpenStack Heat information leak vulnerability

▾ Twilightopenstack-heat · openstack-heatEPSS 0.71%via OSV
CVE-2023-42439High· 7.5
3y ago

GeoNode vulnerable to SSRF Bypass to return internal host data

GeoNode vulnerable to SSRF Bypass to return internal host data

▾ Twilightgeonode · geonodeEPSS 0.96%via OSV
CVE-2023-1633Medium· 6.6
3y ago

OpenStack Barbican credential leak flaw

OpenStack Barbican credential leak flaw

▾ Sunlitbarbican · barbicanEPSS 0.19%via OSV
CVE-2023-1636Medium· 6.0
3y ago

OpenStack Barbican information disclosure vulnerability

OpenStack Barbican information disclosure vulnerability

▾ Sunlitbarbican · barbicanEPSS 0.48%via OSV
CVE-2023-5002Medium· 6.0
3y ago

pgAdmin failed to properly control the server code

pgAdmin failed to properly control the server code

▾ Sunlitpgadmin4 · pgadmin4EPSS 1.8%via OSV
CVE-2023-4806Medium· 5.9
3y ago

A flaw has been identified in glibc

A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the …

▾ Sunlitgnu · glibcEPSS 1.6%via NVD
CVE-2023-43618Medium· 5.3
3y ago

Croc requires senders to provide local IP addresses in cleartext

Croc requires senders to provide local IP addresses in cleartext

▾ Sunlitschollz · github.com/schollz/croc/v9EPSS 0.49%via OSV
CVE-2023-42441Medium· 5.3
3y ago

Vyper has incorrect re-entrancy lock when key is empty string

Vyper has incorrect re-entrancy lock when key is empty string

▾ Sunlitvyper · vyperEPSS 0.51%via OSV
CVE-2023-43621Medium· 4.7
3y ago

Croc may expose secret to local users

Croc may expose secret to local users

▾ Sunlitschollz · github.com/schollz/croc/v9EPSS 0.31%via OSV

Most-affected vendors

By CVEs published in the period.