2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48406 | MEDIUM | 6.7 | 0.1% | Dec 8, 2023 | there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. Thi... |
| CVE-2023-48405 | MEDIUM | 6.7 | 0.1% | Dec 8, 2023 | there is a possible way for the secure world to write to NS memory due to a logic error in the code. This could lead to ... |
| CVE-2023-48401 | MEDIUM | 5.5 | 0.1% | Dec 8, 2023 | In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check.... |
| CVE-2023-48399 | MEDIUM | 5.5 | 0.1% | Dec 8, 2023 | In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a miss... |
| CVE-2023-48397 | MEDIUM | 4.9 | 0.4% | Dec 8, 2023 | In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lea... |
| CVE-2023-23372 | MEDIUM | 6.1 | 0.5% | Dec 8, 2023 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2023-6609 | MEDIUM | 6.1 | 0.4% | Dec 8, 2023 | A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the fi... |
| CVE-2023-6146 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in th... |
| CVE-2023-49487 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management depar... |
| CVE-2023-49486 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department... |
| CVE-2023-49485 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management departmen... |
| CVE-2023-49484 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management depart... |
| CVE-2023-49444 | MEDIUM | 5.4 | 0.5% | Dec 8, 2023 | An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a craft... |
| CVE-2023-45866 | MEDIUM | 6.3 | 7.9% | Dec 8, 2023 | Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encry... |
| CVE-2023-48928 | MEDIUM | 6.1 | 0.5% | Dec 8, 2023 | Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' par... |
| CVE-2023-6599 | MEDIUM | 4.3 | 0.5% | Dec 8, 2023 | Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-46693 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title param... |
| CVE-2023-6578 | MEDIUM | 6.5 | 0.7% | Dec 7, 2023 | A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown ... |
| CVE-2023-6577 | MEDIUM | 4.3 | 1.2% | Dec 7, 2023 | A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affe... |
| CVE-2023-38174 | MEDIUM | 4.3 | 2.2% | Dec 7, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2023-36880 | MEDIUM | 4.8 | 1.6% | Dec 7, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2023-6333 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could all... |
| CVE-2023-48958 | MEDIUM | 5.5 | 0.3% | Dec 7, 2023 | gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589. |
| CVE-2023-47440 | MEDIUM | 6.5 | 1.0% | Dec 7, 2023 | Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be inc... |
| CVE-2023-46871 | MEDIUM | 5.3 | 0.7% | Dec 7, 2023 | GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:30... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now