2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37185 | HIGH | 7.5 | 0.8% | Dec 25, 2023 | C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/b... |
| CVE-2023-28872 | HIGH | 8.8 | 0.8% | Dec 25, 2023 | Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privile... |
| CVE-2023-51772 | HIGH | 8.8 | 0.5% | Dec 25, 2023 | One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct... |
| CVE-2023-49328 | HIGH | 7.2 | 1.0% | Dec 25, 2023 | On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated syst... |
| CVE-2023-31455 | HIGH | 7.5 | 0.6% | Dec 25, 2023 | Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort. |
| CVE-2023-31289 | HIGH | 7.5 | 0.6% | Dec 25, 2023 | Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort. |
| CVE-2023-49880 | HIGH | 7.5 | 0.5% | Dec 25, 2023 | In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending... |
| CVE-2023-43064 | HIGH | 7.8 | 0.2% | Dec 25, 2023 | Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual... |
| CVE-2023-7094 | HIGH | 7.5 | 0.9% | Dec 25, 2023 | A vulnerability classified as problematic was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected by th... |
| CVE-2023-7093 | HIGH | 7.8 | 0.9% | Dec 25, 2023 | A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected ... |
| CVE-2023-7101 | HIGH | 7.8 | 16.7% | Dec 24, 2023 | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerabl... |
| CVE-2023-7091 | HIGH | 8.8 | 0.9% | Dec 24, 2023 | A vulnerability was found in Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown ... |
| CVE-2023-51767 | HIGH | 7 | 0.7% | Dec 24, 2023 | OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) bec... |
| CVE-2023-7090 | HIGH | 8.8 | 0.7% | Dec 23, 2023 | A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated... |
| CVE-2023-5961 | HIGH | 8.8 | 0.4% | Dec 23, 2023 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and... |
| CVE-2023-7002 | HIGH | 7.2 | 45.9% | Dec 23, 2023 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.... |
| CVE-2023-51650 | HIGH | 7.5 | 0.9% | Dec 22, 2023 | Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration i... |
| CVE-2023-51449 | HIGH | 7.5 | 2.3% | Dec 22, 2023 | Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine lear... |
| CVE-2023-51387 | HIGH | 8.8 | 1.5% | Dec 22, 2023 | Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. Th... |
| CVE-2023-50730 | HIGH | 7.5 | 0.8% | Dec 22, 2023 | Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification require... |
| CVE-2023-50714 | HIGH | 8.8 | 0.5% | Dec 22, 2023 | yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. ... |
| CVE-2023-51662 | HIGH | 7.5 | 0.3% | Dec 22, 2023 | The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing appl... |
| CVE-2023-51448 | HIGH | 8.8 | 9.0% | Dec 22, 2023 | Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi)... |
| CVE-2023-50254 | HIGH | 7.8 | 2.1% | Dec 22, 2023 | Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior t... |
| CVE-2023-49085 | HIGH | 8.8 | 84.6% | Dec 22, 2023 | Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now