2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48387 | HIGH | 8.8 | 1.0% | Dec 15, 2023 | TAIWAN-CA(TWCA) JCICSecurityTool fails to check the source website and access locations when executing multiple Registr... |
| CVE-2023-48380 | HIGH | 8 | 0.7% | Dec 15, 2023 | Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a... |
| CVE-2023-6827 | HIGH | 8.8 | 1.3% | Dec 15, 2023 | The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type val... |
| CVE-2023-6826 | HIGH | 7.2 | 1.3% | Dec 15, 2023 | The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the '... |
| CVE-2023-48378 | HIGH | 7.5 | 1.3% | Dec 15, 2023 | Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated r... |
| CVE-2023-48375 | HIGH | 8.8 | 0.7% | Dec 15, 2023 | SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users ar... |
| CVE-2023-48373 | HIGH | 7.5 | 1.3% | Dec 15, 2023 | ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauth... |
| CVE-2023-6831 | HIGH | 8.1 | 3.3% | Dec 15, 2023 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2. |
| CVE-2023-6707 | HIGH | 8.8 | 0.6% | Dec 14, 2023 | Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2023-6706 | HIGH | 8.8 | 0.6% | Dec 14, 2023 | Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engag... |
| CVE-2023-6705 | HIGH | 8.8 | 0.7% | Dec 14, 2023 | Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap ... |
| CVE-2023-6704 | HIGH | 8.8 | 0.7% | Dec 14, 2023 | Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap... |
| CVE-2023-6703 | HIGH | 8.8 | 0.6% | Dec 14, 2023 | Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-6702 | HIGH | 8.8 | 43.2% | Dec 14, 2023 | Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2023-49347 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or ma... |
| CVE-2023-49346 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or ... |
| CVE-2023-49345 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or m... |
| CVE-2023-49344 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed... |
| CVE-2023-49343 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manip... |
| CVE-2023-49342 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or m... |
| CVE-2023-50472 | HIGH | 7.5 | 1.0% | Dec 14, 2023 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. |
| CVE-2023-50471 | HIGH | 7.5 | 1.5% | Dec 14, 2023 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. |
| CVE-2023-49294 | HIGH | 7.5 | 45.6% | Dec 14, 2023 | Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1,... |
| CVE-2023-37457 | HIGH | 8.2 | 1.1% | Dec 14, 2023 | Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0... |
| CVE-2023-50017 | HIGH | 8.8 | 0.4% | Dec 14, 2023 | Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backu... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now