2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5199 | HIGH | 8.8 | 1.4% | Oct 30, 2023 | The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and ... |
| CVE-2023-5833 | HIGH | 8.8 | 0.6% | Oct 30, 2023 | Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. |
| CVE-2023-5844 | HIGH | 7.2 | 0.6% | Oct 30, 2023 | Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0. |
| CVE-2023-44141 | HIGH | 7.8 | 0.3% | Oct 30, 2023 | Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a sp... |
| CVE-2023-46865 | HIGH | 7.2 | 20.3% | Oct 30, 2023 | /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PH... |
| CVE-2023-46863 | HIGH | 7.5 | 0.9% | Oct 30, 2023 | Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/downl... |
| CVE-2023-40685 | HIGH | 7.8 | 0.1% | Oct 29, 2023 | Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability... |
| CVE-2023-5840 | HIGH | 8.8 | 0.7% | Oct 29, 2023 | Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9. |
| CVE-2023-5839 | HIGH | 7.8 | 0.3% | Oct 29, 2023 | Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. |
| CVE-2023-40686 | HIGH | 7.8 | 0.1% | Oct 29, 2023 | Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability... |
| CVE-2023-5426 | HIGH | 7.5 | 0.5% | Oct 28, 2023 | The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2023-5425 | HIGH | 8.8 | 0.5% | Oct 28, 2023 | The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2023-46215 | HIGH | 7.5 | 1.2% | Oct 28, 2023 | Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensi... |
| CVE-2023-46468 | HIGH | 7.8 | 0.5% | Oct 28, 2023 | An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the cus... |
| CVE-2023-43322 | HIGH | 8.8 | 1.1% | Oct 28, 2023 | ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.... |
| CVE-2023-46587 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted... |
| CVE-2023-5834 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, int... |
| CVE-2023-44480 | HIGH | 8.8 | 0.6% | Oct 27, 2023 | Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasu... |
| CVE-2023-40140 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code du... |
| CVE-2023-40131 | HIGH | 7 | 0.1% | Oct 27, 2023 | In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local es... |
| CVE-2023-40130 | HIGH | 7.8 | 0.1% | Oct 27, 2023 | In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. Th... |
| CVE-2023-40129 | HIGH | 8.8 | 0.2% | Oct 27, 2023 | In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could... |
| CVE-2023-40128 | HIGH | 7.8 | 0.1% | Oct 27, 2023 | In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could l... |
| CVE-2023-40125 | HIGH | 7.8 | 0.1% | Oct 27, 2023 | In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. Th... |
| CVE-2023-40120 | HIGH | 7.8 | 0.1% | Oct 27, 2023 | In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now