Weekly digest
Week 42, 2023 (16–22 Oct)
11 new CVEs this week, in line with the recent average. Severity skewed high: 6 high, 55% of the total. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 11 that matter most of the 11 published.
CVE-2023-45805High· 7.8PDM Trojan Lockfile
PDM Trojan Lockfile
CVE-2023-32786High· 7.5Langchain Server-Side Request Forgery vulnerability
Langchain Server-Side Request Forgery vulnerability
CVE-2023-47090HighNATS.io: Adding accounts for just the system account adds auth bypass
NATS.io: Adding accounts for just the system account adds auth bypass
CVE-2023-43802High· 7.3Arduino Create Agent path traversal - local privilege escalation vulnerability
Arduino Create Agent path traversal - local privilege escalation vulnerability
CVE-2023-43800High· 7.3Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
CVE-2023-45683High· 7.1Cross-site Scripting via missing Binding syntax validation
Cross-site Scripting via missing Binding syntax validation
CVE-2023-45815Medium· 6.4ArchiveBox is an open source self-hosted web archiving system
ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same b…
CVE-2023-44690Mediummycli has Inadequate Encryption Strength
mycli has Inadequate Encryption Strength
CVE-2023-45813Medium· 4.6TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link
TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link
CVE-2023-45803Medium· 4.2urllib3's request body not stripped after redirect from 303 status changes request method to GET
urllib3's request body not stripped after redirect from 303 status changes request method to GET
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
vantage6 does not properly delete linked resources when deleting a collaboration
Most-affected vendors
By CVEs published in the period.