VulnSea

Weekly digest

Week 43, 2023 (23–29 Oct)

A busier-than-usual week with 21 new CVEs (recent average about 15). Of those, 1 critical and 9 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. ethyca-fides was the most-affected vendor with 3.

21
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2023-5043High· 7.6PoC
2y ago

Ingress nginx annotation injection causes arbitrary command execution

Ingress nginx annotation injection causes arbitrary command execution

▾ Midnightingress-nginx · k8s.io/ingress-nginxEPSS 2.2%via OSV
CVE-2023-27170High· 7.5PoC
2y ago

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

▾ Midnightxpand-it · write-back_managerEPSS 0.87%via NVD
CVE-2023-46233Critical· 9.1
2y ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because …

▾ Midnightcrypto-js_project · crypto-jsEPSS 0.64%via NVD
CVE-2022-4886High· 8.8
2y ago

Ingress-nginx path sanitization can be bypassed

Ingress-nginx path sanitization can be bypassed

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 1.6%via OSV
CVE-2023-46124High· 8.2
2y ago

Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload

Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.68%via OSV
CVE-2023-46136Medium· 5.7PoC
2y ago

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

▾ Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2023-5367High· 7.8
2y ago

A out-of-bounds write flaw was found in the xorg-x11-server

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRCha…

▾ Twilightx.org · x_serverEPSS 0.62%via NVD
CVE-2023-46128High· 7.7
2y ago

Nautobot vulnerable to exposure of hashed user passwords via REST API

Nautobot vulnerable to exposure of hashed user passwords via REST API

▾ Twilightnautobot · nautobotEPSS 0.53%via OSV
CVE-2023-46215High· 7.5
2y ago

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

▾ Twilightapache-airflow-providers-celery · apache-airflow-providers-celeryEPSS 1.2%via OSV
CVE-2023-4692High· 7.5
2y ago

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack…

▾ Twilightgnu · grub2EPSS 0.54%via NVD
CVE-2023-5574High· 7.0
2y ago

A use-after-free flaw was found in xorg-x11-server-Xvfb

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped f…

▾ Twilightx.org · x_serverEPSS 0.62%via NVD
CVE-2023-46125Medium· 6.5
2y ago

Fides Information Disclosure Vulnerability in Config API Endpoint

Fides Information Disclosure Vulnerability in Config API Endpoint

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.73%via OSV

Most-affected vendors

By CVEs published in the period.