2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6273 | MEDIUM | 5.3 | 0.4% | Dec 6, 2023 | Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerabi... |
| CVE-2023-49248 | MEDIUM | 5.5 | 0.2% | Dec 6, 2023 | Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause u... |
| CVE-2023-46688 | MEDIUM | 6.1 | 0.5% | Dec 6, 2023 | Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect user... |
| CVE-2023-45210 | MEDIUM | 4.3 | 0.5% | Dec 6, 2023 | Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticate... |
| CVE-2023-34439 | MEDIUM | 5.4 | 0.4% | Dec 6, 2023 | Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited... |
| CVE-2023-6527 | MEDIUM | 6.1 | 0.4% | Dec 6, 2023 | The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER h... |
| CVE-2023-26154 | MEDIUM | 5.9 | 1.0% | Dec 6, 2023 | Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubn... |
| CVE-2023-40053 | MEDIUM | 5 | 0.8% | Dec 6, 2023 | A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file ... |
| CVE-2023-6512 | MEDIUM | 6.5 | 1.3% | Dec 6, 2023 | Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to pote... |
| CVE-2023-6511 | MEDIUM | 4.3 | 0.9% | Dec 6, 2023 | Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Aut... |
| CVE-2023-48940 | MEDIUM | 5.4 | 0.5% | Dec 6, 2023 | A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary ... |
| CVE-2023-28876 | MEDIUM | 4.3 | 0.5% | Dec 6, 2023 | A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delet... |
| CVE-2023-28875 | MEDIUM | 5.4 | 0.4% | Dec 6, 2023 | A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code ... |
| CVE-2023-24547 | MEDIUM | 6.5 | 0.3% | Dec 6, 2023 | On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in cl... |
| CVE-2023-49283 | MEDIUM | 5.3 | 2.2% | Dec 5, 2023 | microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which cont... |
| CVE-2023-49282 | MEDIUM | 5.3 | 2.2% | Dec 5, 2023 | msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained t... |
| CVE-2023-46736 | MEDIUM | 6.5 | 0.4% | Dec 5, 2023 | EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Req... |
| CVE-2023-45084 | MEDIUM | 6.1 | 0.2% | Dec 5, 2023 | An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause ... |
| CVE-2023-45083 | MEDIUM | 4.4 | 0.2% | Dec 5, 2023 | An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authentic... |
| CVE-2023-44298 | MEDIUM | 6.8 | 0.2% | Dec 5, 2023 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security v... |
| CVE-2023-44297 | MEDIUM | 6.8 | 0.3% | Dec 5, 2023 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security v... |
| CVE-2023-6180 | MEDIUM | 5.3 | 0.6% | Dec 5, 2023 | The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consump... |
| CVE-2023-42579 | MEDIUM | 5.3 | 0.2% | Dec 5, 2023 | Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in An... |
| CVE-2023-42576 | MEDIUM | 6.8 | 0.4% | Dec 5, 2023 | Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass aut... |
| CVE-2023-42575 | MEDIUM | 6.8 | 0.4% | Dec 5, 2023 | Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass aut... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now