2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42847 | HIGH | 7.5 | 0.9% | Oct 25, 2023 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An... |
| CVE-2023-42844 | HIGH | 7.5 | 1.5% | Oct 25, 2023 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12... |
| CVE-2023-42841 | HIGH | 7.8 | 0.4% | Oct 25, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.... |
| CVE-2023-41976 | HIGH | 8.8 | 1.5% | Oct 25, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17.1 and iPadOS 17.1, w... |
| CVE-2023-40447 | HIGH | 8.8 | 1.5% | Oct 25, 2023 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iO... |
| CVE-2023-40445 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | The issue was addressed with improved UI handling. This issue is fixed in iOS 17.1 and iPadOS 17.1. A device may persist... |
| CVE-2023-40423 | HIGH | 7.8 | 0.5% | Oct 25, 2023 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 1... |
| CVE-2023-40404 | HIGH | 7.8 | 1.1% | Oct 25, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.1. An app m... |
| CVE-2023-40401 | HIGH | 7.5 | 1.0% | Oct 25, 2023 | The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may... |
| CVE-2023-32359 | HIGH | 7.5 | 0.9% | Oct 25, 2023 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS ... |
| CVE-2023-5753 | HIGH | 8.8 | 0.9% | Oct 25, 2023 | Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c |
| CVE-2023-5728 | HIGH | 7.5 | 1.2% | Oct 25, 2023 | During garbage collection extra operations were performed on a object that should not be. This could have led to a poten... |
| CVE-2023-5724 | HIGH | 7.5 | 1.6% | Oct 25, 2023 | Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. T... |
| CVE-2023-5717 | HIGH | 7.8 | 0.9% | Oct 25, 2023 | A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be e... |
| CVE-2023-5671 | HIGH | 7.8 | 0.2% | Oct 25, 2023 | HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software ... |
| CVE-2023-5472 | HIGH | 8.8 | 1.2% | Oct 25, 2023 | Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit hea... |
| CVE-2023-5363 | HIGH | 7.5 | 3.3% | Oct 25, 2023 | Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead... |
| CVE-2023-5311 | HIGH | 8.8 | 1.5% | Oct 25, 2023 | The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2023-4692 | HIGH | 7.8 | 0.5% | Oct 25, 2023 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a s... |
| CVE-2023-4608 | HIGH | 7.2 | 0.3% | Oct 25, 2023 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted AP... |
| CVE-2023-4607 | HIGH | 8.8 | 0.4% | Oct 25, 2023 | An authenticated XCC user can change permissions for any user through a crafted API command. |
| CVE-2023-4606 | HIGH | 8.1 | 0.5% | Oct 25, 2023 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command... |
| CVE-2023-46654 | HIGH | 8.1 | 1.4% | Oct 25, 2023 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory dur... |
| CVE-2023-46346 | HIGH | 7.5 | 0.8% | Oct 25, 2023 | In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModul... |
| CVE-2023-46204 | HIGH | 8.8 | 0.3% | Oct 25, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Muller Digital Inc. Duplicate Theme plugin <= 0.1.6 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now