2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21418 | HIGH | 7.1 | 0.7% | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to pat... |
| CVE-2023-21417 | HIGH | 7.1 | 0.7% | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnera... |
| CVE-2023-45886 | HIGH | 7.5 | 1.4% | Nov 21, 2023 | The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending... |
| CVE-2023-48310 | HIGH | 7.5 | 1.1% | Nov 20, 2023 | TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtere... |
| CVE-2023-48051 | HIGH | 7.5 | 0.2% | Nov 20, 2023 | An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption pad... |
| CVE-2023-48192 | HIGH | 7.8 | 0.4% | Nov 20, 2023 | An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracero... |
| CVE-2023-47172 | HIGH | 7.8 | 0.2% | Nov 20, 2023 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Ser... |
| CVE-2023-48111 | HIGH | 7.5 | 0.8% | Nov 20, 2023 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentContro... |
| CVE-2023-48110 | HIGH | 7.5 | 0.8% | Nov 20, 2023 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControl... |
| CVE-2023-48109 | HIGH | 7.5 | 0.8% | Nov 20, 2023 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentCon... |
| CVE-2023-4824 | HIGH | 8.8 | 0.4% | Nov 20, 2023 | The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow atta... |
| CVE-2023-48293 | HIGH | 8.8 | 0.4% | Nov 20, 2023 | The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-si... |
| CVE-2023-38885 | HIGH | 8.8 | 0.4% | Nov 20, 2023 | OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole ap... |
| CVE-2023-38884 | HIGH | 7.5 | 0.9% | Nov 20, 2023 | An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows ... |
| CVE-2023-38879 | HIGH | 7.5 | 3.7% | Nov 20, 2023 | The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a direc... |
| CVE-2023-48292 | HIGH | 8.8 | 22.9% | Nov 20, 2023 | The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior ... |
| CVE-2023-48241 | HIGH | 7.5 | 72.8% | Nov 20, 2023 | XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, a... |
| CVE-2023-48240 | HIGH | 8.8 | 0.7% | Nov 20, 2023 | XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents a... |
| CVE-2023-48221 | HIGH | 8.8 | 0.9% | Nov 20, 2023 | wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to ver... |
| CVE-2023-6196 | HIGH | 8.8 | 0.3% | Nov 20, 2023 | The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2023-48090 | HIGH | 7.1 | 0.3% | Nov 20, 2023 | GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329. |
| CVE-2023-6045 | HIGH | 7.8 | 0.2% | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through t... |
| CVE-2023-5593 | HIGH | 7.8 | 0.2% | Nov 20, 2023 | The out-of-bounds write vulnerability in the Windows-based SecuExtender SSL VPN Client software version 4.0.4.0 could al... |
| CVE-2023-43612 | HIGH | 7.8 | 0.2% | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservat... |
| CVE-2023-3116 | HIGH | 7.1 | 0.2% | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now