2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29125 | HIGH | 8 | 0.3% | Nov 5, 2024 | A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700. |
| CVE-2023-29122 | MEDIUM | 6.7 | 0.2% | Nov 5, 2024 | Under certain conditions, access to service libraries is granted to account they should not have access to. |
| CVE-2023-29121 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system. |
| CVE-2023-29120 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s priv... |
| CVE-2023-29119 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.ph... |
| CVE-2023-29118 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.p... |
| CVE-2023-29117 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox... |
| CVE-2023-29116 | MEDIUM | 4.3 | 0.2% | Nov 5, 2024 | Under certain conditions, through a request directed to the Waybox Enel X web management application, information like W... |
| CVE-2023-29115 | MEDIUM | 6.5 | 0.3% | Nov 5, 2024 | In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service... |
| CVE-2023-29114 | MEDIUM | 5.7 | 0.2% | Nov 5, 2024 | System logs could be accessed through web management application due to a lack of access control. An attacker can obta... |
| CVE-2023-52920 | MEDIUM | 5.5 | 0.2% | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from st... |
| CVE-2023-34445 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible f... |
| CVE-2023-34444 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possib... |
| CVE-2023-34443 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (X... |
| CVE-2023-52045 | MEDIUM | 6.1 | 0.3% | Oct 31, 2024 | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vuln... |
| CVE-2023-52044 | CRITICAL | 9.8 | 0.8% | Oct 31, 2024 | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files wi... |
| CVE-2023-52066 | HIGH | 7.2 | 0.3% | Oct 30, 2024 | http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter. |
| CVE-2023-5816 | MEDIUM | 4.9 | 0.5% | Oct 30, 2024 | The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and inclu... |
| CVE-2023-26248 | MEDIUM | 5.3 | 0.2% | Oct 25, 2024 | The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information fo... |
| CVE-2023-50355 | MEDIUM | 5.3 | 0.2% | Oct 23, 2024 | HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information t... |
| CVE-2023-50310 | HIGH | 7.5 | 0.4% | Oct 23, 2024 | IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses ... |
| CVE-2023-52919 | MEDIUM | 5.5 | 0.2% | Oct 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix possible NULL pointer dereference in ... |
| CVE-2023-52918 | MEDIUM | 5.5 | 0.2% | Oct 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() retu... |
| CVE-2023-52917 | — | — | — | Oct 21, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-6243 | MEDIUM | 4.3 | 0.2% | Oct 19, 2024 | The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now