2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28570 | HIGH | 7.8 | 0.1% | Nov 7, 2023 | Memory corruption while processing audio effects. |
| CVE-2023-28556 | HIGH | 7.8 | 0.1% | Nov 7, 2023 | Cryptographic issue in HLOS during key management. |
| CVE-2023-28545 | HIGH | 7.8 | 0.1% | Nov 7, 2023 | Memory corruption in TZ Secure OS while loading an app ELF. |
| CVE-2023-24852 | HIGH | 7.8 | 0.1% | Nov 7, 2023 | Memory Corruption in Core due to secure memory access by user while loading modem image. |
| CVE-2023-21671 | HIGH | 7.8 | 0.1% | Nov 7, 2023 | Memory Corruption in Core during syscall for Sectools Fuse comparison feature. |
| CVE-2023-41036 | HIGH | 7.8 | 0.3% | Nov 7, 2023 | Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC... |
| CVE-2023-47004 | HIGH | 8.8 | 1.0% | Nov 6, 2023 | Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to exe... |
| CVE-2023-5454 | HIGH | 7.5 | 0.6% | Nov 6, 2023 | The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, all... |
| CVE-2023-5355 | HIGH | 8.1 | 0.7% | Nov 6, 2023 | The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files,... |
| CVE-2023-5082 | HIGH | 7.2 | 0.7% | Nov 6, 2023 | The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using ... |
| CVE-2023-39345 | HIGH | 7.5 | 0.5% | Nov 6, 2023 | strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked... |
| CVE-2023-46728 | HIGH | 7.5 | 6.0% | Nov 6, 2023 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid ... |
| CVE-2023-44398 | HIGH | 8.8 | 1.0% | Nov 6, 2023 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2023-41378 | HIGH | 7.5 | 0.7% | Nov 6, 2023 | In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.1... |
| CVE-2023-5964 | HIGH | 7.2 | 0.8% | Nov 6, 2023 | The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exch... |
| CVE-2023-45163 | HIGH | 7.2 | 0.9% | Nov 6, 2023 | The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does n... |
| CVE-2023-45161 | HIGH | 7.2 | 0.8% | Nov 6, 2023 | The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does n... |
| CVE-2023-3399 | HIGH | 7.7 | 0.5% | Nov 6, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting... |
| CVE-2023-5823 | HIGH | 8.8 | 0.2% | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions. |
| CVE-2023-47186 | HIGH | 8.8 | 0.2% | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versio... |
| CVE-2023-46781 | HIGH | 8.8 | 0.2% | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Murg Current Menu Item for Custom Post Types plugin <= 1.5 ver... |
| CVE-2023-46780 | HIGH | 8.8 | 0.2% | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Alter plugin <= 1.0 versions. |
| CVE-2023-46779 | HIGH | 8.8 | 0.2% | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in EasyRecipe plugin <= 3.5.3251 versions. |
| CVE-2023-46778 | HIGH | 8.8 | 0.2% | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in TheFreeWindows Auto Limit Posts Reloaded plugin <= 2.5 versions. |
| CVE-2023-46777 | HIGH | 8.8 | 0.2% | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha p... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now