VulnSea

Weekly digest

Week 48, 2023 (27 Nov – 3 Dec)

A busier-than-usual week with 18 new CVEs (recent average about 14). Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. apache-superset was the most-affected vendor with 6.

18
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2023-48022Critical· 9.8PoC
2y ago

Ray has arbitrary code execution via jobs submission API

Ray has arbitrary code execution via jobs submission API

▾ Abyssalray · rayEPSS 84%via OSV
CVE-2023-49097High· 8.1
2y ago

ZITADEL Account Takeover via Malicious Host Header Injection

ZITADEL Account Takeover via Malicious Host Header Injection

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.77%via OSV
CVE-2023-49081High· 7.2
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…

▾ Twilightaiohttp · aiohttpEPSS 0.88%via NVD
CVE-2023-40610High· 7.3
2y ago

Apache Superset - Elevation of Privilege

Apache Superset - Elevation of Privilege

▾ Twilightapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2023-42504Medium· 6.5
2y ago

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-49926Medium· 6.1
2y ago

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-49277Medium· 6.1
2y ago

Reflected XSS Vulnerability in dpaste

Reflected XSS Vulnerability in dpaste

▾ Sunlitdpaste · dpasteEPSS 0.52%via OSV
CVE-2023-49083Medium· 5.9
2y ago

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

▾ Sunlitcryptography · cryptographyEPSS 0.98%via OSV
CVE-2023-42502Medium· 5.4
2y ago

Apache Superset Open Redirect vulnerability

Apache Superset Open Redirect vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.83%via OSV
CVE-2023-49082Medium· 5.3
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…

▾ Sunlitaiohttp · aiohttpEPSS 0.95%via NVD
CVE-2023-34054Medium· 5.3
2y ago

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an …

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an …

▾ Sunlitbroadcom · reactor_nettyEPSS 0.91%via NVD
CVE-2023-48369Medium· 5.3
2y ago

Mattermost Uncontrolled Resource Consumption vulnerability

Mattermost Uncontrolled Resource Consumption vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.63%via OSV

Most-affected vendors

By CVEs published in the period.