2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29065 | MEDIUM | 4.3 | 0.3% | Nov 28, 2023 | The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat ... |
| CVE-2023-29064 | MEDIUM | 4.3 | 0.3% | Nov 28, 2023 | The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets ... |
| CVE-2023-29061 | MEDIUM | 5.2 | 0.4% | Nov 28, 2023 | There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can pote... |
| CVE-2023-30588 | MEDIUM | 5.3 | 1.2% | Nov 28, 2023 | When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect ter... |
| CVE-2023-29060 | MEDIUM | 5.7 | 0.3% | Nov 28, 2023 | The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited... |
| CVE-2023-49078 | MEDIUM | 6.1 | 0.5% | Nov 28, 2023 | raptor-web is a CMS for game server communities that can be used to host information and keep track of players. In versi... |
| CVE-2023-48121 | MEDIUM | 5.3 | 0.8% | Nov 28, 2023 | An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 2023040... |
| CVE-2023-42504 | MEDIUM | 6.5 | 1.1% | Nov 28, 2023 | An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports,... |
| CVE-2023-45286 | MEDIUM | 5.9 | 0.7% | Nov 28, 2023 | A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered... |
| CVE-2023-42505 | MEDIUM | 4.3 | 1.0% | Nov 28, 2023 | An authenticated user with read permissions on database connections metadata could potentially access sensitive informat... |
| CVE-2023-42502 | MEDIUM | 5.4 | 0.8% | Nov 28, 2023 | An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing t... |
| CVE-2023-48042 | MEDIUM | 6.1 | 0.5% | Nov 28, 2023 | Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote at... |
| CVE-2023-6359 | MEDIUM | 6.1 | 0.4% | Nov 28, 2023 | A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could ... |
| CVE-2023-5981 | MEDIUM | 5.9 | 1.3% | Nov 28, 2023 | A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from resp... |
| CVE-2023-4667 | MEDIUM | 4.8 | 0.4% | Nov 28, 2023 | The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fie... |
| CVE-2023-34055 | MEDIUM | 6.5 | 1.2% | Nov 28, 2023 | In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially cra... |
| CVE-2023-4220 | MEDIUM | 6.1 | 76.1% | Nov 28, 2023 | Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in C... |
| CVE-2023-24023 | MEDIUM | 6.8 | 1.3% | Nov 28, 2023 | Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 t... |
| CVE-2023-6226 | MEDIUM | 4.3 | 0.5% | Nov 28, 2023 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in... |
| CVE-2023-6225 | MEDIUM | 5.4 | 0.5% | Nov 28, 2023 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2023-48713 | MEDIUM | 5.3 | 0.9% | Nov 28, 2023 | Knative Serving builds on Kubernetes to support deploying and serving of applications and functions as serverless contai... |
| CVE-2023-32065 | MEDIUM | 5.8 | 0.5% | Nov 28, 2023 | OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order t... |
| CVE-2023-32064 | MEDIUM | 4.3 | 0.5% | Nov 28, 2023 | OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can acce... |
| CVE-2023-32063 | MEDIUM | 5 | 0.5% | Nov 28, 2023 | OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access... |
| CVE-2023-5960 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.5... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now