2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32967 | MEDIUM | 6.5 | 0.3% | Feb 2, 2024 | An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
| CVE-2023-6673 | MEDIUM | 6.1 | 0.3% | Feb 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cybe... |
| CVE-2023-6672 | MEDIUM | 5.4 | 0.3% | Feb 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cybe... |
| CVE-2023-47144 | MEDIUM | 6.1 | 0.3% | Feb 2, 2024 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This... |
| CVE-2023-51820 | MEDIUM | 6.8 | 0.5% | Feb 2, 2024 | An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitr... |
| CVE-2023-51072 | MEDIUM | 5.4 | 1.3% | Feb 2, 2024 | A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 a... |
| CVE-2023-49118 | MEDIUM | 5.5 | 0.1% | Feb 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read. |
| CVE-2023-43756 | MEDIUM | 5.5 | 0.1% | Feb 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read. |
| CVE-2023-38020 | MEDIUM | 4.3 | 0.4% | Feb 2, 2024 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files... |
| CVE-2023-38019 | MEDIUM | 6.5 | 1.0% | Feb 2, 2024 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An att... |
| CVE-2023-46159 | MEDIUM | 6.5 | 0.7% | Feb 2, 2024 | IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service f... |
| CVE-2023-50941 | MEDIUM | 5.4 | 0.3% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain acc... |
| CVE-2023-50938 | MEDIUM | 4.3 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a... |
| CVE-2023-50935 | MEDIUM | 6.5 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker ... |
| CVE-2023-50934 | MEDIUM | 5.3 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when co... |
| CVE-2023-50328 | MEDIUM | 5.3 | 0.5% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM... |
| CVE-2023-46344 | MEDIUM | 5.4 | 0.6% | Feb 2, 2024 | A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an att... |
| CVE-2023-50933 | MEDIUM | 6.1 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which... |
| CVE-2023-50327 | MEDIUM | 5.3 | 0.5% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized fil... |
| CVE-2023-6221 | MEDIUM | 6.5 | 0.6% | Feb 1, 2024 | The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the prog... |
| CVE-2023-47256 | MEDIUM | 5.5 | 0.4% | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of ... |
| CVE-2023-51520 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugi... |
| CVE-2023-51514 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr Team CBX ... |
| CVE-2023-51509 | MEDIUM | 6.1 | 0.4% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss Registra... |
| CVE-2023-51506 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WPCS – ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now