2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42488 | HIGH | 7.5 | 0.8% | Oct 25, 2023 | EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2023-41372 | HIGH | 7.8 | 0.2% | Oct 25, 2023 | The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of... |
| CVE-2023-41255 | HIGH | 8.8 | 0.4% | Oct 25, 2023 | The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on t... |
| CVE-2023-3112 | HIGH | 7.8 | 0.2% | Oct 25, 2023 | A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker wi... |
| CVE-2023-39740 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token an... |
| CVE-2023-39739 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token... |
| CVE-2023-39737 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send cra... |
| CVE-2023-39736 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token... |
| CVE-2023-39735 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token an... |
| CVE-2023-39734 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the cha... |
| CVE-2023-39733 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send... |
| CVE-2023-39732 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token a... |
| CVE-2023-39619 | HIGH | 7.5 | 1.1% | Oct 25, 2023 | ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpS... |
| CVE-2023-39219 | HIGH | 7.5 | 0.6% | Oct 25, 2023 | PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java ... |
| CVE-2023-38041 | HIGH | 7 | 0.7% | Oct 25, 2023 | A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a p... |
| CVE-2023-37913 | HIGH | 8.8 | 1.1% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver... |
| CVE-2023-37912 | HIGH | 8.8 | 1.2% | Oct 25, 2023 | XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior t... |
| CVE-2023-37910 | HIGH | 8.1 | 0.6% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with t... |
| CVE-2023-37909 | HIGH | 8.8 | 1.6% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver... |
| CVE-2023-31582 | HIGH | 7.5 | 0.6% | Oct 25, 2023 | jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less. |
| CVE-2023-27377 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application ... |
| CVE-2023-27376 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 an... |
| CVE-2023-27375 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 an... |
| CVE-2023-27259 | HIGH | 7.5 | 0.5% | Oct 25, 2023 | Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows e... |
| CVE-2023-27258 | HIGH | 7.5 | 0.5% | Oct 25, 2023 | Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier all... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now