2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36648 | HIGH | 8.2 | 1.0% | Dec 12, 2023 | Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticat... |
| CVE-2023-36647 | HIGH | 7.5 | 0.8% | Dec 12, 2023 | A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows rem... |
| CVE-2023-36646 | HIGH | 8.8 | 0.8% | Dec 12, 2023 | Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker wit... |
| CVE-2023-49805 | HIGH | 8.8 | 0.4% | Dec 11, 2023 | Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with... |
| CVE-2023-49804 | HIGH | 7.8 | 0.3% | Dec 11, 2023 | Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login pass... |
| CVE-2023-49803 | HIGH | 7.5 | 0.3% | Dec 11, 2023 | @koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0... |
| CVE-2023-6035 | HIGH | 8.8 | 0.9% | Dec 11, 2023 | The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an ... |
| CVE-2023-6671 | HIGH | 8.8 | 0.2% | Dec 11, 2023 | A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an e... |
| CVE-2023-6194 | HIGH | 7.1 | 0.3% | Dec 11, 2023 | In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document typ... |
| CVE-2023-6186 | HIGH | 8.8 | 0.8% | Dec 11, 2023 | Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in m... |
| CVE-2023-6185 | HIGH | 8.8 | 1.0% | Dec 11, 2023 | Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attack... |
| CVE-2023-49964 | HIGH | 8.8 | 34.7% | Dec 11, 2023 | An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder... |
| CVE-2023-5500 | HIGH | 8.8 | 1.0% | Dec 11, 2023 | This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code... |
| CVE-2023-49355 | HIGH | 7.5 | 1.2% | Dec 11, 2023 | decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" inpu... |
| CVE-2023-6659 | HIGH | 7.5 | 0.6% | Dec 11, 2023 | A vulnerability, which was classified as critical, has been found in Campcodes Web-Based Student Clearance System 1.0. T... |
| CVE-2023-6656 | HIGH | 7.5 | 0.9% | Dec 10, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has be... |
| CVE-2023-50455 | HIGH | 7.5 | 0.7% | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature... |
| CVE-2023-5869 | HIGH | 8.8 | 4.3% | Dec 10, 2023 | A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overfl... |
| CVE-2023-50449 | HIGH | 7.5 | 1.2% | Dec 10, 2023 | JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey... |
| CVE-2023-50446 | HIGH | 7.8 | 0.2% | Dec 10, 2023 | An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow an... |
| CVE-2023-6654 | HIGH | 8.8 | 1.7% | Dec 10, 2023 | A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown... |
| CVE-2023-5756 | HIGH | 8.8 | 0.3% | Dec 9, 2023 | The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to... |
| CVE-2023-28868 | HIGH | 8.1 | 0.9% | Dec 9, 2023 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operati... |
| CVE-2023-28523 | HIGH | 7.8 | 0.3% | Dec 9, 2023 | IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds... |
| CVE-2023-49797 | HIGH | 7.8 | 0.3% | Dec 9, 2023 | PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now