2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6731 | MEDIUM | 4.3 | 0.4% | May 2, 2024 | The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on... |
| CVE-2023-6214 | HIGH | 7.5 | 0.6% | May 2, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2023-50685 | HIGH | 7.5 | 1.2% | May 2, 2024 | An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script t... |
| CVE-2023-47727 | MEDIUM | 4.3 | 0.3% | May 2, 2024 | IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could al... |
| CVE-2023-37244 | HIGH | 7 | 0.2% | May 2, 2024 | The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows s... |
| CVE-2023-41971 | HIGH | 7.8 | 0.2% | May 2, 2024 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows a... |
| CVE-2023-41970 | HIGH | 7.8 | 0.1% | May 2, 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair A... |
| CVE-2023-28798 | CRITICAL | 9.8 | 0.4% | May 2, 2024 | An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code ex... |
| CVE-2023-51631 | MEDIUM | 6.8 | 1.0% | May 2, 2024 | D-Link DIR-X3260 prog.cgi SetUsersSettings Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnera... |
| CVE-2023-46295 | CRITICAL | 9.8 | 0.9% | May 1, 2024 | An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server... |
| CVE-2023-46294 | LOW | 3.4 | 0.1% | May 1, 2024 | An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypte... |
| CVE-2023-26793 | CRITICAL | 9.8 | 0.7% | May 1, 2024 | libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. |
| CVE-2023-23022 | MEDIUM | 6.1 | 0.5% | May 1, 2024 | Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows at... |
| CVE-2023-23021 | MEDIUM | 6.1 | 0.5% | May 1, 2024 | Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to exec... |
| CVE-2023-23019 | MEDIUM | 5.4 | 0.3% | May 1, 2024 | Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and ema... |
| CVE-2023-7241 | HIGH | 7.9 | 0.2% | May 1, 2024 | Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious s... |
| CVE-2023-49606 | CRITICAL | 9.8 | 63.1% | May 1, 2024 | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A... |
| CVE-2023-47212 | CRITICAL | 9.8 | 1.4% | May 1, 2024 | A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially craft... |
| CVE-2023-47166 | HIGH | 8.8 | 0.6% | May 1, 2024 | A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A spec... |
| CVE-2023-40533 | — | — | — | May 1, 2024 | Rejected reason: This CVE ID is a duplicate of CVE-2022-40468 |
| CVE-2023-52653 | MEDIUM | 5.5 | 0.3% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix a memleak in gss_import_v2_context The... |
| CVE-2023-52652 | MEDIUM | 5.5 | 0.3% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: NTB: fix possible name leak in ntb_register_device(... |
| CVE-2023-52651 | — | — | — | May 1, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-52650 | MEDIUM | 5.5 | 0.3% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/tegra: dsi: Add missing check for of_find_devic... |
| CVE-2023-52649 | HIGH | 7.8 | 0.3% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Avoid reading beyond LUT array When the ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now