2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30590 | HIGH | 7.5 | 1.5% | Nov 28, 2023 | The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, th... |
| CVE-2023-40056 | HIGH | 8.8 | 4.8% | Nov 28, 2023 | SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be expl... |
| CVE-2023-48848 | HIGH | 7.5 | 0.9% | Nov 28, 2023 | An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server ... |
| CVE-2023-49062 | HIGH | 7.5 | 0.6% | Nov 28, 2023 | Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulatio... |
| CVE-2023-46589 | HIGH | 7.5 | 2.7% | Nov 28, 2023 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 throug... |
| CVE-2023-49314 | HIGH | 7.8 | 4.3% | Nov 28, 2023 | Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection ag... |
| CVE-2023-6239 | HIGH | 8.8 | 0.6% | Nov 28, 2023 | Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specif... |
| CVE-2023-6201 | HIGH | 8.8 | 1.6% | Nov 28, 2023 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Comp... |
| CVE-2023-42004 | HIGH | 8.8 | 1.1% | Nov 28, 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute ... |
| CVE-2023-6151 | HIGH | 7.5 | 0.6% | Nov 28, 2023 | Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b... |
| CVE-2023-6150 | HIGH | 7.5 | 0.6% | Nov 28, 2023 | Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b... |
| CVE-2023-34054 | HIGH | 7.5 | 0.9% | Nov 28, 2023 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a u... |
| CVE-2023-34053 | HIGH | 7.5 | 1.1% | Nov 28, 2023 | In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that m... |
| CVE-2023-4226 | HIGH | 8.8 | 2.4% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers wit... |
| CVE-2023-4225 | HIGH | 8.8 | 1.8% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers... |
| CVE-2023-4224 | HIGH | 8.8 | 1.8% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers ... |
| CVE-2023-4223 | HIGH | 8.8 | 1.8% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers... |
| CVE-2023-4222 | HIGH | 8.8 | 3.5% | Nov 28, 2023 | Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to u... |
| CVE-2023-4221 | HIGH | 8.8 | 3.5% | Nov 28, 2023 | Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to up... |
| CVE-2023-49075 | HIGH | 7.2 | 1.4% | Nov 28, 2023 | The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introdu... |
| CVE-2023-6219 | HIGH | 7.2 | 1.2% | Nov 28, 2023 | The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the... |
| CVE-2023-4398 | HIGH | 7.5 | 0.9% | Nov 28, 2023 | An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ... |
| CVE-2023-30585 | HIGH | 7.5 | 1.5% | Nov 28, 2023 | A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows u... |
| CVE-2023-29770 | HIGH | 8.8 | 0.9% | Nov 28, 2023 | In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file w... |
| CVE-2023-49030 | HIGH | 7.5 | 0.9% | Nov 27, 2023 | SQL Injection vulnerability in32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now