2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40539 | — | — | — | Jul 18, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-40223 | — | — | — | Jul 18, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-40159 | — | — | — | Jul 18, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-50304 | HIGH | 8.2 | 0.6% | Jul 18, 2024 | IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE)... |
| CVE-2023-6708 | MEDIUM | 5.4 | 0.3% | Jul 18, 2024 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all vers... |
| CVE-2023-43971 | MEDIUM | 6.1 | 0.4% | Jul 17, 2024 | Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode ... |
| CVE-2023-42010 | LOW | 3.7 | 0.3% | Jul 17, 2024 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitiv... |
| CVE-2023-4976 | CRITICAL | 9.3 | 0.4% | Jul 17, 2024 | A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an un... |
| CVE-2023-7272 | HIGH | 7.5 | 0.6% | Jul 17, 2024 | In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to caus... |
| CVE-2023-52291 | MEDIUM | 4.7 | 1.6% | Jul 17, 2024 | In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not str... |
| CVE-2023-7013 | MEDIUM | 4.7 | 0.2% | Jul 16, 2024 | Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potent... |
| CVE-2023-7012 | CRITICAL | 9.6 | 0.3% | Jul 16, 2024 | Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convi... |
| CVE-2023-7011 | MEDIUM | 6.5 | 0.4% | Jul 16, 2024 | Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to... |
| CVE-2023-7010 | HIGH | 8.8 | 0.4% | Jul 16, 2024 | Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-4860 | CRITICAL | 9.6 | 0.4% | Jul 16, 2024 | Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromis... |
| CVE-2023-31456 | MEDIUM | 5.4 | 0.2% | Jul 16, 2024 | There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be ... |
| CVE-2023-52886 | MEDIUM | 6.4 | 0.3% | Jul 16, 2024 | In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descri... |
| CVE-2023-52290 | HIGH | 8.1 | 0.6% | Jul 16, 2024 | In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from... |
| CVE-2023-49566 | HIGH | 8.8 | 0.8% | Jul 15, 2024 | In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2... |
| CVE-2023-46801 | HIGH | 8.8 | 1.2% | Jul 15, 2024 | In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution v... |
| CVE-2023-41916 | MEDIUM | 6.5 | 0.7% | Jul 15, 2024 | In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql ... |
| CVE-2023-52885 | HIGH | 7.8 | 0.2% | Jul 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() Aft... |
| CVE-2023-39329 | MEDIUM | 6.5 | 0.6% | Jul 13, 2024 | A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a cra... |
| CVE-2023-39327 | MEDIUM | 4.3 | 0.5% | Jul 13, 2024 | A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuou... |
| CVE-2023-41093 | LOW | 3.1 | 0.2% | Jul 12, 2024 | Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capa... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now