Weekly digest
Week 45, 2023 (6–12 Nov)
13 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 4 high, 54% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2023-47246Critical· 9.8CISA KEV0dayPoCIn SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
CVE-2023-47248Critical· 9.8PoCPyArrow: Arbitrary code execution when loading a malicious data file
PyArrow: Arbitrary code execution when loading a malicious data file
CVE-2023-46850Critical· 9.8Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
CVE-2023-46446High· 8.1AsyncSSH Rogue Session Attack
AsyncSSH Rogue Session Attack
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2023-41378High· 7.5Calico Typha denial of service vulnerability
Calico Typha denial of service vulnerability
CVE-2023-47111High· 7.3ZITADEL race condition in lockout policy execution
ZITADEL race condition in lockout policy execution
CVE-2023-4061Medium· 6.5A flaw was found in wildfly-core
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and ob…
CVE-2023-46734Medium· 6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_sa…
CVE-2023-5090Medium· 6.0A flaw was found in KVM
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
CVE-2023-46445Medium· 5.3AsyncSSH Rogue Extension Negotiation
AsyncSSH Rogue Extension Negotiation
CVE-2023-47114Medium· 4.3Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
Most-affected vendors
By CVEs published in the period.