2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41102 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not ... |
| CVE-2023-39548 | HIGH | 8.8 | 0.7% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39547 | HIGH | 8.8 | 0.6% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39546 | HIGH | 8.8 | 0.6% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39545 | HIGH | 8.8 | 0.7% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39544 | HIGH | 8.8 | 0.6% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-38322 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference th... |
| CVE-2023-38320 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer derefere... |
| CVE-2023-38315 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer deref... |
| CVE-2023-38313 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can b... |
| CVE-2023-47675 | HIGH | 7.2 | 1.0% | Nov 17, 2023 | CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary ... |
| CVE-2023-38130 | HIGH | 8.1 | 0.4% | Nov 17, 2023 | Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to d... |
| CVE-2023-45382 | HIGH | 7.5 | 0.8% | Nov 17, 2023 | In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can downl... |
| CVE-2023-47687 | HIGH | 8.8 | 0.3% | Nov 16, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in VJInfotech Woo Custom and Sequential Order Number plugin <= 2.6.0 ver... |
| CVE-2023-47686 | HIGH | 8.8 | 0.3% | Nov 16, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 ve... |
| CVE-2023-47688 | HIGH | 8.8 | 0.3% | Nov 16, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube SpeedLoad plugin <= 0.6.3 versions. |
| CVE-2023-6020 | HIGH | 7.5 | 14.7% | Nov 16, 2023 | LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication. |
| CVE-2023-46214 | HIGH | 8.8 | 89.1% | Nov 16, 2023 | In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet la... |
| CVE-2023-48134 | HIGH | 7.5 | 0.7% | Nov 16, 2023 | nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. |
| CVE-2023-48056 | HIGH | 7.5 | 0.5% | Nov 16, 2023 | PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabil... |
| CVE-2023-48055 | HIGH | 7.5 | 0.4% | Nov 16, 2023 | SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the dis... |
| CVE-2023-48054 | HIGH | 7.4 | 0.3% | Nov 16, 2023 | Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host... |
| CVE-2023-48053 | HIGH | 7.5 | 0.4% | Nov 16, 2023 | Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabilit... |
| CVE-2023-48052 | HIGH | 7.4 | 0.3% | Nov 16, 2023 | Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and... |
| CVE-2023-6038 | HIGH | 7.5 | 4.3% | Nov 16, 2023 | A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to re... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now