2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5797 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t... |
| CVE-2023-5650 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, ... |
| CVE-2023-4397 | MEDIUM | 4.4 | 0.2% | Nov 28, 2023 | A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, US... |
| CVE-2023-37926 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware ve... |
| CVE-2023-37925 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t... |
| CVE-2023-35139 | MEDIUM | 6.1 | 0.5% | Nov 28, 2023 | A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.3... |
| CVE-2023-35136 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 throug... |
| CVE-2023-47437 | MEDIUM | 5.4 | 0.5% | Nov 28, 2023 | A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting... |
| CVE-2023-49145 | MEDIUM | 5.4 | 1.2% | Nov 27, 2023 | Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user ... |
| CVE-2023-46355 | MEDIUM | 5.3 | 0.5% | Nov 27, 2023 | In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal informati... |
| CVE-2023-42366 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. |
| CVE-2023-42365 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar functio... |
| CVE-2023-42364 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk patte... |
| CVE-2023-5885 | MEDIUM | 6.5 | 1.1% | Nov 27, 2023 | The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login... |
| CVE-2023-42363 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. |
| CVE-2023-32062 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | OroPlatform is a package that assists system and user calendar management. Back-office users can access information from... |
| CVE-2023-48034 | MEDIUM | 6.1 | 0.2% | Nov 27, 2023 | An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless key... |
| CVE-2023-5958 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the bac... |
| CVE-2023-5942 | MEDIUM | 5.4 | 0.5% | Nov 27, 2023 | The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2023-5845 | MEDIUM | 5.3 | 0.6% | Nov 27, 2023 | The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthentic... |
| CVE-2023-5738 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could... |
| CVE-2023-5737 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users wit... |
| CVE-2023-5653 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers bef... |
| CVE-2023-5641 | MEDIUM | 6.1 | 0.4% | Nov 27, 2023 | The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a... |
| CVE-2023-5620 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of th... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now