VulnSea

Weekly digest

Week 39, 2023 (25 Sep – 1 Oct)

16 new CVEs this week, in line with the recent average. Of those, 2 critical and 5 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Cisco was the most-affected vendor with 3.

16
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2023-43364Critical· 9.8PoC
3y ago

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

▾ Abyssalsearchor · searchorEPSS 2.9%via OSV
CVE-2023-41419Critical· 9.8
3y ago

Gevent allows remote attacker to escalate privileges

Gevent allows remote attacker to escalate privileges

▾ Midnightgevent · geventEPSS 1.8%via OSV
CVE-2023-20033High· 8.6
3y ago

Cisco IOS XE Software for Catalyst 3650 and Catalyst 3850 Switches Denial of Service Vulnerability

A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) c…

▾ TwilightCisco · Cisco IOS XE SoftwareEPSS 0.65%via CSAF
CVE-2023-40581High· 8.3
3y ago

yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`

yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`

▾ Twilightyt-dlp · yt-dlpEPSS 1.3%via OSV
CVE-2023-44464High· 7.8
3y ago

pretix allows Pillow to parse EPS files

pretix allows Pillow to parse EPS files

▾ Twilightpretix · pretixEPSS 0.30%via OSV
CVE-2023-5077High· 7.6
3y ago

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.44%via OSV
CVE-2023-42753High· 7.0
3y ago

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decre…

▾ Twilightlinux · linux_kernelEPSS 0.51%via NVD
CVE-2023-41333Medium· 6.9
3y ago

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.41%via OSV
CVE-2023-43645Medium· 5.9
3y ago

OpenFGA Vulnerable to DoS from circular relationship definitions

OpenFGA Vulnerable to DoS from circular relationship definitions

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.75%via OSV
CVE-2023-20176Medium· 5.8
3y ago

Cisco Aironet Access Points Denial of Service

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacke…

▾ SunlitCisco · Cisco Aironet Access Point SoftwareEPSS 0.65%via CSAF
CVE-2023-40026Medium· 5.0
3y ago

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.50%via OSV
CVE-2023-20268Medium· 4.7
3y ago

Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability (CVE-2023-20268)

A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient managemen…

▾ SunlitCisco · Cisco Business Wireless Access Point SoftwareEPSS 0.24%via CSAF

Most-affected vendors

By CVEs published in the period.