2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51949 | HIGH | 8.8 | 0.3% | Jan 12, 2024 | Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/back... |
| CVE-2023-49261 | HIGH | 7.5 | 0.5% | Jan 12, 2024 | The "tokenKey" value used in user authorization is visible in the HTML source of the login page. |
| CVE-2023-49259 | HIGH | 7.5 | 0.3% | Jan 12, 2024 | The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and... |
| CVE-2023-49257 | HIGH | 8.8 | 0.3% | Jan 12, 2024 | An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execut... |
| CVE-2023-49256 | HIGH | 7.5 | 0.5% | Jan 12, 2024 | It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded... |
| CVE-2023-49254 | HIGH | 8.8 | 0.7% | Jan 12, 2024 | Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destinati... |
| CVE-2023-5356 | HIGH | 8.8 | 0.8% | Jan 12, 2024 | Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting... |
| CVE-2023-0437 | HIGH | 7.5 | 1.1% | Jan 12, 2024 | When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an i... |
| CVE-2023-49568 | HIGH | 7.5 | 0.7% | Jan 12, 2024 | A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an a... |
| CVE-2023-48909 | HIGH | 8.8 | 0.9% | Jan 12, 2024 | An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function. |
| CVE-2023-6740 | HIGH | 7.8 | 0.2% | Jan 12, 2024 | Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user t... |
| CVE-2023-6735 | HIGH | 7.8 | 0.3% | Jan 12, 2024 | Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escal... |
| CVE-2023-34061 | HIGH | 7.5 | 0.5% | Jan 12, 2024 | Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated att... |
| CVE-2023-6040 | HIGH | 7.8 | 0.3% | Jan 12, 2024 | An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables:... |
| CVE-2023-40250 | HIGH | 8.8 | 0.6% | Jan 12, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows O... |
| CVE-2023-46474 | HIGH | 7.2 | 23.4% | Jan 11, 2024 | File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a c... |
| CVE-2023-50123 | HIGH | 8.1 | 0.6% | Jan 11, 2024 | The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This co... |
| CVE-2023-51782 | HIGH | 7 | 0.3% | Jan 11, 2024 | An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because ... |
| CVE-2023-51781 | HIGH | 7 | 0.3% | Jan 11, 2024 | An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free becaus... |
| CVE-2023-51780 | HIGH | 7 | 0.5% | Jan 11, 2024 | An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because o... |
| CVE-2023-50671 | HIGH | 7.8 | 0.4% | Jan 11, 2024 | In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write ... |
| CVE-2023-51749 | HIGH | 8.8 | 0.3% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NO... |
| CVE-2023-51748 | HIGH | 8.8 | 0.3% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is ... |
| CVE-2023-50159 | HIGH | 8.8 | 0.3% | Jan 11, 2024 | In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrar... |
| CVE-2023-6979 | HIGH | 8.8 | 1.1% | Jan 11, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now