2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6893 | HIGH | 7.5 | 70.2% | Dec 17, 2023 | A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as proble... |
| CVE-2023-6891 | HIGH | 7.8 | 0.3% | Dec 17, 2023 | A vulnerability has been found in PeaZip 9.4.0 and classified as problematic. Affected by this vulnerability is an unkno... |
| CVE-2023-50784 | HIGH | 7.5 | 1.9% | Dec 16, 2023 | A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker... |
| CVE-2023-39340 | HIGH | 7.5 | 2.4% | Dec 16, 2023 | A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific reque... |
| CVE-2023-50728 | HIGH | 7.5 | 0.7% | Dec 15, 2023 | octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2,... |
| CVE-2023-50265 | HIGH | 7.5 | 0.9% | Dec 15, 2023 | Bazarr manages and downloads subtitles. Prior to 1.3.1, the /api/swaggerui/static endpoint in bazarr/app/ui.py does not ... |
| CVE-2023-50264 | HIGH | 7.5 | 0.9% | Dec 15, 2023 | Bazarr manages and downloads subtitles. Prior to 1.3.1, Bazarr contains an arbitrary file read in /system/backup/downloa... |
| CVE-2023-50723 | HIGH | 8.8 | 1.2% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone... |
| CVE-2023-50722 | HIGH | 8.8 | 0.7% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there ... |
| CVE-2023-50721 | HIGH | 8.8 | 78.8% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, t... |
| CVE-2023-50719 | HIGH | 7.5 | 83.5% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-... |
| CVE-2023-6680 | HIGH | 8.1 | 0.4% | Dec 15, 2023 | An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior... |
| CVE-2023-49749 | HIGH | 8.8 | 0.3% | Dec 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in SureTriggers SureTriggers – Connect All Your Plugins, Apps, Tools & A... |
| CVE-2023-49744 | HIGH | 8.8 | 0.2% | Dec 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Gift Up Gift Up Gift Cards for WordPress and WooCommerce.This issue a... |
| CVE-2023-49197 | HIGH | 8.8 | 0.3% | Dec 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case b... |
| CVE-2023-49159 | HIGH | 7.5 | 0.4% | Dec 15, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: ... |
| CVE-2023-3904 | HIGH | 7.5 | 0.7% | Dec 15, 2023 | An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5... |
| CVE-2023-50870 | HIGH | 8.8 | 0.3% | Dec 15, 2023 | In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible |
| CVE-2023-46116 | HIGH | 8.8 | 1.3% | Dec 15, 2023 | Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applicati... |
| CVE-2023-49898 | HIGH | 7.2 | 2.3% | Dec 15, 2023 | In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on t... |
| CVE-2023-33217 | HIGH | 7.5 | 0.7% | Dec 15, 2023 | By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent ... |
| CVE-2023-6837 | HIGH | 8.2 | 0.5% | Dec 15, 2023 | Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order... |
| CVE-2023-6836 | HIGH | 7.5 | 0.5% | Dec 15, 2023 | Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely ava... |
| CVE-2023-48394 | HIGH | 8.8 | 0.9% | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file wit... |
| CVE-2023-48389 | HIGH | 7.5 | 1.3% | Dec 15, 2023 | Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated rem... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now