2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6238 | MEDIUM | 6.7 | 0.3% | Nov 21, 2023 | A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user cou... |
| CVE-2023-48299 | MEDIUM | 5.3 | 0.7% | Nov 21, 2023 | TorchServe is a tool for serving and scaling PyTorch models in production. Starting in version 0.1.0 and prior to versio... |
| CVE-2023-47643 | MEDIUM | 5.3 | 3.0% | Nov 21, 2023 | SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection... |
| CVE-2023-20265 | MEDIUM | 5.4 | 0.5% | Nov 21, 2023 | A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated,... |
| CVE-2023-20208 | MEDIUM | 4.8 | 0.5% | Nov 21, 2023 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond... |
| CVE-2023-6211 | MEDIUM | 6.5 | 0.5% | Nov 21, 2023 | If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker... |
| CVE-2023-6210 | MEDIUM | 6.5 | 0.6% | Nov 21, 2023 | When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable... |
| CVE-2023-6209 | MEDIUM | 6.5 | 1.4% | Nov 21, 2023 | Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be... |
| CVE-2023-6206 | MEDIUM | 5.4 | 0.6% | Nov 21, 2023 | The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prom... |
| CVE-2023-6205 | MEDIUM | 6.5 | 0.9% | Nov 21, 2023 | It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to a... |
| CVE-2023-6204 | MEDIUM | 6.5 | 0.8% | Nov 21, 2023 | On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak m... |
| CVE-2023-49061 | MEDIUM | 6.1 | 0.3% | Nov 21, 2023 | An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerab... |
| CVE-2023-48124 | MEDIUM | 5.4 | 0.6% | Nov 21, 2023 | Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email... |
| CVE-2023-28802 | MEDIUM | 5.4 | 0.2% | Nov 21, 2023 | An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to d... |
| CVE-2023-5599 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x thr... |
| CVE-2023-5598 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ... |
| CVE-2023-5553 | MEDIUM | 6.8 | 0.3% | Nov 21, 2023 | During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t... |
| CVE-2023-46935 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in u... |
| CVE-2023-21416 | MEDIUM | 6.5 | 0.7% | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable t... |
| CVE-2023-6144 | MEDIUM | 4.8 | 0.4% | Nov 21, 2023 | Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any use... |
| CVE-2023-6142 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. Wi... |
| CVE-2023-6199 | MEDIUM | 6.5 | 1.4% | Nov 20, 2023 | Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulne... |
| CVE-2023-6178 | MEDIUM | 6.5 | 0.8% | Nov 20, 2023 | An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing applicatio... |
| CVE-2023-6062 | MEDIUM | 6.5 | 1.0% | Nov 20, 2023 | An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on t... |
| CVE-2023-47311 | MEDIUM | 6.1 | 0.4% | Nov 20, 2023 | An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now