VulnSea

Weekly digest

Week 40, 2023 (2–8 Oct)

10 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 3 high, 50% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

10
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2023-43654Critical· 9.8PoC
2y ago

TorchServe Server-Side Request Forgery vulnerability

TorchServe Server-Side Request Forgery vulnerability

▾ Abyssaltorchserve · torchserveEPSS 36%via OSV
CVE-2023-43261High· 7.5PoC
2y ago

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

▾ Midnightmilesight · ur5x_firmwareEPSS 60%via NVD
CVE-2023-32188Critical
2y ago

JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

▾ Midnightneuvector · github.com/neuvector/neuvectorEPSS 0.48%via OSV
CVE-2023-4570High· 8.8
2y ago

NI MeasurementLink Python Services Improper Access Restriction vulnerability

NI MeasurementLink Python Services Improper Access Restriction vulnerability

▾ Twilightni-measurementlink-service · ni-measurementlink-serviceEPSS 0.28%via OSV
CVE-2023-43804Medium· 5.9PoC
2y ago

`Cookie` HTTP header isn't stripped on cross-origin redirects

`Cookie` HTTP header isn't stripped on cross-origin redirects

▾ Twilighturllib3 · urllib3EPSS 1.2%via OSV
CVE-2023-43810High· 7.5
2y ago

opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics

opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics

▾ Twilightopentelemetry-instrumentation · opentelemetry-instrumentationEPSS 0.69%via OSV
CVE-2023-4237Medium· 6.5
2y ago

Ansible may expose private key

Ansible may expose private key

▾ Sunlitansible-core · ansible-coreEPSS 0.25%via OSV
CVE-2023-44378Medium· 5.5
2y ago

gnark unsoundness in variable comparison / non-unique binary decomposition

gnark unsoundness in variable comparison / non-unique binary decomposition

▾ Sunlitconsensys · github.com/consensys/gnarkEPSS 0.22%via OSV
CVE-2023-3576Medium· 5.5
2y ago

A memory leak flaw was found in Libtiff's tiffcrop utility

A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, r…

▾ Sunlitlibtiff · libtiffEPSS 0.35%via NVD
CVE-2023-44389Low· 3.1
2y ago

Zope management interface vulnerable to stored cross site scripting via the title property

Zope management interface vulnerable to stored cross site scripting via the title property

▾ Sunlitzope · zopeEPSS 0.40%via OSV

Most-affected vendors

By CVEs published in the period.