VulnSea

Weekly digest

Week 46, 2023 (13–19 Nov)

A heavy week: 29 new CVEs, well above the recent average of about 13. Severity skewed high: 9 critical and 9 high, 62% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. vim was the most-affected vendor with 7.

29
New CVEs
9
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 29 published.

CVE-2023-6019Critical· 9.8PoC
2y ago

Ray OS Command Injection vulnerability

Ray OS Command Injection vulnerability

▾ Abyssalray · rayEPSS 75%via OSV
CVE-2023-6021Critical· 9.3PoC
2y ago

Ray Path Traversal vulnerability

Ray Path Traversal vulnerability

▾ Abyssalray · rayEPSS 37%via OSV
CVE-2023-6020Critical· 9.3PoC
2y ago

Ray Missing Authorization vulnerability

Ray Missing Authorization vulnerability

▾ Abyssalray · rayEPSS 15%via OSV
CVE-2023-47630High· 7.1⚠ Exploited0day
2y ago

Attacker can cause Kyverno user to unintentionally consume insecure image

Attacker can cause Kyverno user to unintentionally consume insecure image

▾ Abyssalkyverno · github.com/kyverno/kyvernoEPSS 0.26%via OSV
CVE-2023-48659Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48658Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48657Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48656Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48655Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-47117High· 7.5PoC
2y ago

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

▾ Midnightlabel-studio · label-studioEPSS 4.1%via OSV
CVE-2023-43902Critical· 9.8
2y ago

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

▾ Midnightemudhra · emsignerEPSS 0.83%via NVD
CVE-2023-6022High· 8.8
2y ago

Cross-Site Request Forgery vulnerability in Prefect

Cross-Site Request Forgery vulnerability in Prefect

▾ Twilightprefect · prefectEPSS 0.39%via OSV

Most-affected vendors

By CVEs published in the period.