2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37822 | HIGH | 8.2 | 0.3% | Oct 3, 2024 | The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serve... |
| CVE-2023-7273 | MEDIUM | 6.8 | 0.2% | Oct 1, 2024 | Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has ... |
| CVE-2023-3441 | CRITICAL | 9.1 | 0.5% | Oct 1, 2024 | An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not s... |
| CVE-2023-46175 | MEDIUM | 4.9 | 0.3% | Sep 26, 2024 | IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which... |
| CVE-2023-52950 | MEDIUM | 5.3 | 0.1% | Sep 26, 2024 | Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent befor... |
| CVE-2023-52949 | MEDIUM | 5.5 | 0.2% | Sep 26, 2024 | Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for... |
| CVE-2023-52948 | MEDIUM | 5 | 0.1% | Sep 26, 2024 | Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agen... |
| CVE-2023-52947 | LOW | 3.3 | 0.2% | Sep 26, 2024 | Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Busines... |
| CVE-2023-52946 | HIGH | 8.2 | 0.5% | Sep 26, 2024 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synolog... |
| CVE-2023-51157 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obt... |
| CVE-2023-25189 | LOW | 3.3 | 0.1% | Sep 25, 2024 | BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web E... |
| CVE-2023-5359 | HIGH | 7.5 | 0.8% | Sep 25, 2024 | The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including... |
| CVE-2023-26691 | HIGH | 7.2 | 1.2% | Sep 25, 2024 | Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafte... |
| CVE-2023-26690 | HIGH | 8.8 | 0.7% | Sep 25, 2024 | File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/E... |
| CVE-2023-26689 | CRITICAL | 9.8 | 0.6% | Sep 25, 2024 | An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted ... |
| CVE-2023-26688 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via... |
| CVE-2023-26687 | HIGH | 8.8 | 1.2% | Sep 25, 2024 | Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information ... |
| CVE-2023-26686 | CRITICAL | 9.8 | 0.7% | Sep 25, 2024 | File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image uplo... |
| CVE-2023-7282 | MEDIUM | 4.3 | 0.2% | Sep 23, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinc... |
| CVE-2023-7281 | MEDIUM | 4.3 | 0.2% | Sep 23, 2024 | Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perfor... |
| CVE-2023-46948 | MEDIUM | 5.4 | 0.4% | Sep 23, 2024 | A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attac... |
| CVE-2023-47480 | HIGH | 8.4 | 0.2% | Sep 20, 2024 | An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () functi... |
| CVE-2023-27584 | CRITICAL | 9.8 | 29.8% | Sep 19, 2024 | Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native ... |
| CVE-2023-30464 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack. |
| CVE-2023-41612 | HIGH | 8.8 | 0.2% | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now