Weekly digest
Week 39, 2023 (25 Sep – 1 Oct)
16 new CVEs this week, in line with the recent average. Of those, 2 critical and 5 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Cisco was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 16 published.
CVE-2023-43364Critical· 9.8PoCSearchor CLI's Search vulnerable to Arbitrary Code using Eval
Searchor CLI's Search vulnerable to Arbitrary Code using Eval
CVE-2023-41419Critical· 9.8Gevent allows remote attacker to escalate privileges
Gevent allows remote attacker to escalate privileges
CVE-2023-20033High· 8.6Cisco IOS XE Software for Catalyst 3650 and Catalyst 3850 Switches Denial of Service Vulnerability
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) c…
CVE-2023-40581High· 8.3yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
CVE-2023-44464High· 7.8pretix allows Pillow to parse EPS files
pretix allows Pillow to parse EPS files
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-42753High· 7.0An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel
An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decre…
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
OpenFGA Vulnerable to DoS from circular relationship definitions
CVE-2023-20176Medium· 5.8Cisco Aironet Access Points Denial of Service
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacke…
CVE-2023-40026Medium· 5.0Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
CVE-2023-20268Medium· 4.7Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability (CVE-2023-20268)
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient managemen…
Most-affected vendors
By CVEs published in the period.