VulnSea

Weekly digest

Week 45, 2023 (6–12 Nov)

13 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 4 high, 54% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

13
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2023-47246Critical· 9.8CISA KEV0dayPoC
2y ago

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

▾ Hadalsysaid · sysaidEPSS 99%via NVD
CVE-2023-47248Critical· 9.8PoC
2y ago

PyArrow: Arbitrary code execution when loading a malicious data file

PyArrow: Arbitrary code execution when loading a malicious data file

▾ Abyssalpyarrow · pyarrowEPSS 15%via OSV
CVE-2023-46850Critical· 9.8
2y ago

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

▾ Midnightopenvpn · openvpnEPSS 2.0%via NVD
CVE-2023-46446High· 8.1
2y ago

AsyncSSH Rogue Session Attack

AsyncSSH Rogue Session Attack

▾ Twilightasyncssh · asyncsshEPSS 0.87%via OSV
CVE-2023-5954High· 7.5
2y ago

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.72%via OSV
CVE-2023-41378High· 7.5
2y ago

Calico Typha denial of service vulnerability

Calico Typha denial of service vulnerability

▾ Twilightprojectcalico · github.com/projectcalico/calicoEPSS 0.72%via OSV
CVE-2023-47111High· 7.3
2y ago

ZITADEL race condition in lockout policy execution

ZITADEL race condition in lockout policy execution

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.52%via OSV
CVE-2023-4061Medium· 6.5
2y ago

A flaw was found in wildfly-core

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and ob…

▾ Sunlitredhat · jboss_enterprise_application_platformEPSS 0.83%via NVD
CVE-2023-46734Medium· 6.1
2y ago

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_sa…

▾ Sunlitsensiolabs · symfonyEPSS 0.69%via NVD
CVE-2023-5090Medium· 6.0
2y ago

A flaw was found in KVM

A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.

▾ Sunlitlinux · linux_kernelEPSS 0.23%via NVD
CVE-2023-46445Medium· 5.3
2y ago

AsyncSSH Rogue Extension Negotiation

AsyncSSH Rogue Extension Negotiation

▾ Sunlitasyncssh · asyncsshEPSS 0.59%via OSV
CVE-2023-47114Medium· 4.3
2y ago

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.61%via OSV

Most-affected vendors

By CVEs published in the period.