2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22611 | HIGH | 7.5 | 0.6% | Jan 31, 2023 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information ... |
| CVE-2023-22610 | HIGH | 7.5 | 0.6% | Jan 31, 2023 | A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server... |
| CVE-2023-24163 | CRITICAL | 9.8 | 1.4% | Jan 31, 2023 | SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator tem... |
| CVE-2023-24162 | CRITICAL | 9.8 | 1.3% | Jan 31, 2023 | Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readOb... |
| CVE-2023-24829 | HIGH | 8.8 | 1.2% | Jan 31, 2023 | Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe... |
| CVE-2023-0593 | MEDIUM | 5.5 | 0.4% | Jan 31, 2023 | A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attac... |
| CVE-2023-0592 | MEDIUM | 5.5 | 0.4% | Jan 31, 2023 | A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attack... |
| CVE-2023-0591 | MEDIUM | 5.5 | 0.4% | Jan 31, 2023 | ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the... |
| CVE-2023-22900 | CRITICAL | 9.8 | 1.0% | Jan 31, 2023 | Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vu... |
| CVE-2023-23582 | CRITICAL | 9.8 | 0.8% | Jan 30, 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could a... |
| CVE-2023-22389 | MEDIUM | 6.5 | 0.5% | Jan 30, 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configura... |
| CVE-2023-24020 | CRITICAL | 9.8 | 0.6% | Jan 30, 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple at... |
| CVE-2023-22315 | HIGH | 7.8 | 0.1% | Jan 30, 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does... |
| CVE-2023-0097 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of ... |
| CVE-2023-0074 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before ... |
| CVE-2023-0071 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputti... |
| CVE-2023-0033 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could a... |
| CVE-2023-24830 | HIGH | 7.5 | 1.3% | Jan 30, 2023 | Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench ... |
| CVE-2023-0512 | HIGH | 7.8 | 0.5% | Jan 30, 2023 | Divide By Zero in GitHub repository vim/vim prior to 9.0.1247. |
| CVE-2023-0581 | MEDIUM | 5.3 | 0.7% | Jan 30, 2023 | The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side valid... |
| CVE-2023-0266 | HIGH | 7 | 3.7% | Jan 30, 2023 | A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 i... |
| CVE-2023-0240 | HIGH | 7.8 | 0.3% | Jan 30, 2023 | There is a logic error in io_uring's implementation which can be used to trigger a use-after-free vulnerability leading ... |
| CVE-2023-0474 | HIGH | 8.8 | 0.5% | Jan 30, 2023 | Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install... |
| CVE-2023-0473 | HIGH | 8.8 | 0.7% | Jan 30, 2023 | Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially ex... |
| CVE-2023-0472 | HIGH | 8.8 | 0.7% | Jan 30, 2023 | Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now