2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48704 | HIGH | 7.5 | 0.5% | Dec 22, 2023 | ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports i... |
| CVE-2023-48670 | HIGH | 7.8 | 0.2% | Dec 22, 2023 | Dell SupportAssist for Home PCs version 3.14.1 and prior versions contain a privilege escalation vulnerability in the i... |
| CVE-2023-42465 | HIGH | 7 | 0.5% | Dec 22, 2023 | Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because applicatio... |
| CVE-2023-51661 | HIGH | 8.6 | 0.6% | Dec 22, 2023 | Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the br... |
| CVE-2023-49391 | HIGH | 7.5 | 1.0% | Dec 22, 2023 | An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial o... |
| CVE-2023-49356 | HIGH | 7.5 | 0.7% | Dec 22, 2023 | A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3... |
| CVE-2023-43741 | HIGH | 7 | 0.2% | Dec 22, 2023 | A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.2... |
| CVE-2023-43116 | HIGH | 7.8 | 0.3% | Dec 22, 2023 | A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the bu... |
| CVE-2023-24609 | HIGH | 7.5 | 0.7% | Dec 22, 2023 | Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shar... |
| CVE-2023-51713 | HIGH | 7.5 | 4.2% | Dec 22, 2023 | make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandl... |
| CVE-2023-7053 | HIGH | 8.8 | 0.8% | Dec 22, 2023 | A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulne... |
| CVE-2023-51708 | HIGH | 8.6 | 0.5% | Dec 22, 2023 | Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated... |
| CVE-2023-7024 | HIGH | 8.8 | 7.4% | Dec 21, 2023 | Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit... |
| CVE-2023-49084 | HIGH | 8.8 | 63.8% | Dec 21, 2023 | Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). ... |
| CVE-2023-48298 | HIGH | 7.5 | 0.6% | Dec 21, 2023 | ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports ... |
| CVE-2023-6847 | HIGH | 7.5 | 0.8% | Dec 21, 2023 | An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mod... |
| CVE-2023-46649 | HIGH | 7 | 0.2% | Dec 21, 2023 | A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploi... |
| CVE-2023-46648 | HIGH | 7.5 | 0.7% | Dec 21, 2023 | An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that allowed an attacker to brut... |
| CVE-2023-46647 | HIGH | 8.8 | 0.6% | Dec 21, 2023 | Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the man... |
| CVE-2023-41097 | HIGH | 7.5 | 0.3% | Dec 21, 2023 | An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding O... |
| CVE-2023-6546 | HIGH | 7 | 0.8% | Dec 21, 2023 | A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execu... |
| CVE-2023-44482 | HIGH | 8.8 | 0.7% | Dec 21, 2023 | Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsick... |
| CVE-2023-44481 | HIGH | 8.8 | 0.6% | Dec 21, 2023 | Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearn... |
| CVE-2023-32747 | HIGH | 7.5 | 0.4% | Dec 21, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects Wo... |
| CVE-2023-7037 | HIGH | 8.8 | 0.7% | Dec 21, 2023 | A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the func... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now