2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28777 | HIGH | 8.8 | 0.7% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDas... |
| CVE-2023-25047 | HIGH | 7.2 | 0.7% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP... |
| CVE-2023-25045 | HIGH | 7.2 | 0.5% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP... |
| CVE-2023-5099 | HIGH | 8.8 | 0.9% | Oct 31, 2023 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in... |
| CVE-2023-38994 | HIGH | 7.8 | 0.3% | Oct 31, 2023 | The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaint... |
| CVE-2023-45996 | HIGH | 8.8 | 1.1% | Oct 31, 2023 | SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker ... |
| CVE-2023-45899 | HIGH | 7.5 | 0.8% | Oct 31, 2023 | An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attack... |
| CVE-2023-46129 | HIGH | 7.5 | 0.4% | Oct 31, 2023 | NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise,... |
| CVE-2023-46478 | HIGH | 8.8 | 1.0% | Oct 30, 2023 | An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data ... |
| CVE-2023-45672 | HIGH | 7.5 | 1.4% | Oct 30, 2023 | Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerabilit... |
| CVE-2023-45956 | HIGH | 7.5 | 0.5% | Oct 30, 2023 | An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveW... |
| CVE-2023-42323 | HIGH | 8.8 | 0.4% | Oct 30, 2023 | Cross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code vi... |
| CVE-2023-42803 | HIGH | 8.8 | 0.5% | Oct 30, 2023 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestri... |
| CVE-2023-41891 | HIGH | 8.8 | 0.9% | Oct 30, 2023 | FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior... |
| CVE-2023-47101 | HIGH | 7.8 | 0.2% | Oct 30, 2023 | The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalati... |
| CVE-2023-45780 | HIGH | 7.3 | 0.1% | Oct 30, 2023 | In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to lo... |
| CVE-2023-21398 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to ... |
| CVE-2023-21397 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to loc... |
| CVE-2023-21396 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to... |
| CVE-2023-21393 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to lo... |
| CVE-2023-21392 | HIGH | 8.8 | 0.2% | Oct 30, 2023 | In Bluetooth, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of ... |
| CVE-2023-21391 | HIGH | 7.5 | 0.4% | Oct 30, 2023 | In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could ... |
| CVE-2023-21390 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to l... |
| CVE-2023-21389 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead... |
| CVE-2023-21388 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalati... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now