VulnSea

Weekly digest

Week 42, 2023 (16–22 Oct)

11 new CVEs this week, in line with the recent average. Severity skewed high: 6 high, 55% of the total. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

11
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2023-45805High· 7.8
2y ago

PDM Trojan Lockfile

PDM Trojan Lockfile

▾ Twilightpdm · pdmEPSS 0.51%via OSV
CVE-2023-32786High· 7.5
2y ago

Langchain Server-Side Request Forgery vulnerability

Langchain Server-Side Request Forgery vulnerability

▾ Twilightlangchain · langchainEPSS 0.70%via OSV
CVE-2023-47090High
2y ago

NATS.io: Adding accounts for just the system account adds auth bypass

NATS.io: Adding accounts for just the system account adds auth bypass

▾ Twilightnats-io · github.com/nats-io/nats-server/v2EPSS 0.66%via OSV
CVE-2023-43802High· 7.3
2y ago

Arduino Create Agent path traversal - local privilege escalation vulnerability

Arduino Create Agent path traversal - local privilege escalation vulnerability

▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.35%via OSV
CVE-2023-43800High· 7.3
2y ago

Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability

Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability

▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.21%via OSV
CVE-2023-45683High· 7.1
2y ago

Cross-site Scripting via missing Binding syntax validation

Cross-site Scripting via missing Binding syntax validation

▾ Twilightcrewjam · github.com/crewjam/samlEPSS 0.43%via OSV
CVE-2023-45815Medium· 6.4
2y ago

ArchiveBox is an open source self-hosted web archiving system

ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same b…

▾ Sunlitarchivebox · archiveboxEPSS 0.68%via NVD
CVE-2023-44690Medium
2y ago

mycli has Inadequate Encryption Strength

mycli has Inadequate Encryption Strength

▾ Sunlitmycli · mycliEPSS 0.22%via OSV
CVE-2023-45813Medium· 4.6
2y ago

TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link

TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link

▾ Sunlittorbot · torbotEPSS 0.80%via OSV
CVE-2023-45803Medium· 4.2
2y ago

urllib3's request body not stripped after redirect from 303 status changes request method to GET

urllib3's request body not stripped after redirect from 303 status changes request method to GET

▾ Sunliturllib3 · urllib3EPSS 0.54%via OSV
CVE-2023-41881Low· 3.7
2y ago

vantage6 does not properly delete linked resources when deleting a collaboration

vantage6 does not properly delete linked resources when deleting a collaboration

▾ Sunlitvantage6 · vantage6EPSS 0.32%via OSV

Most-affected vendors

By CVEs published in the period.