2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1714 | HIGH | 8.8 | 1.4% | Nov 1, 2023 | Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote au... |
| CVE-2023-1713 | HIGH | 8.8 | 1.2% | Nov 1, 2023 | Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apa... |
| CVE-2023-4197 | HIGH | 8.8 | 32.8% | Nov 1, 2023 | Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when c... |
| CVE-2023-5899 | HIGH | 8.8 | 0.3% | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5898 | HIGH | 8.8 | 0.3% | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5897 | HIGH | 8.8 | 0.2% | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1. |
| CVE-2023-5893 | HIGH | 8.8 | 0.3% | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5889 | HIGH | 8.2 | 0.4% | Nov 1, 2023 | Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-3955 | HIGH | 8.8 | 3.4% | Oct 31, 2023 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat... |
| CVE-2023-3676 | HIGH | 8.8 | 11.7% | Oct 31, 2023 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat... |
| CVE-2023-45955 | HIGH | 7.5 | 0.6% | Oct 31, 2023 | An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write bind... |
| CVE-2023-37832 | HIGH | 7.5 | 0.6% | Oct 31, 2023 | A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute forc... |
| CVE-2023-5739 | HIGH | 7.8 | 0.2% | Oct 31, 2023 | Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege. |
| CVE-2023-46723 | HIGH | 7.5 | 0.4% | Oct 31, 2023 | lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable t... |
| CVE-2023-46248 | HIGH | 8.8 | 1.1% | Oct 31, 2023 | Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 ar... |
| CVE-2023-46245 | HIGH | 7.2 | 1.5% | Oct 31, 2023 | Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Templ... |
| CVE-2023-46240 | HIGH | 7.5 | 0.6% | Oct 31, 2023 | CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a d... |
| CVE-2023-46239 | HIGH | 7.5 | 0.8% | Oct 31, 2023 | quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by seri... |
| CVE-2023-46992 | HIGH | 7.5 | 0.5% | Oct 31, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral ... |
| CVE-2023-46236 | HIGH | 7.5 | 0.5% | Oct 31, 2023 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-si... |
| CVE-2023-42658 | HIGH | 7.8 | 0.3% | Oct 31, 2023 | Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profi... |
| CVE-2023-40050 | HIGH | 8.8 | 1.2% | Oct 31, 2023 | Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec... |
| CVE-2023-37243 | HIGH | 7.8 | 0.2% | Oct 31, 2023 | The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM w... |
| CVE-2023-5098 | HIGH | 8.1 | 0.6% | Oct 31, 2023 | The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like s... |
| CVE-2023-46978 | HIGH | 7.5 | 0.5% | Oct 31, 2023 | TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WI... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now