2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27257 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows... |
| CVE-2023-26580 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present... |
| CVE-2023-26578 | HIGH | 8.8 | 1.5% | Oct 25, 2023 | Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload d... |
| CVE-2023-26576 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext... |
| CVE-2023-26575 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext... |
| CVE-2023-26574 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extractio... |
| CVE-2023-26571 | HIGH | 7.5 | 0.6% | Oct 25, 2023 | Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modific... |
| CVE-2023-26570 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier a... |
| CVE-2023-26219 | HIGH | 8.8 | 0.4% | Oct 25, 2023 | The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver... |
| CVE-2023-20273 | HIGH | 7.2 | 89.6% | Oct 25, 2023 | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c... |
| CVE-2023-33517 | HIGH | 7.5 | 0.7% | Oct 23, 2023 | carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System). |
| CVE-2023-5633 | HIGH | 7.8 | 0.3% | Oct 23, 2023 | The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in... |
| CVE-2023-45966 | HIGH | 7.5 | 0.6% | Oct 23, 2023 | umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability. |
| CVE-2023-46603 | HIGH | 8.8 | 0.5% | Oct 23, 2023 | In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function... |
| CVE-2023-46602 | HIGH | 8.8 | 0.5% | Oct 23, 2023 | In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in... |
| CVE-2023-33839 | HIGH | 8.8 | 1.1% | Oct 23, 2023 | IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the sys... |
| CVE-2023-33837 | HIGH | 7.5 | 0.3% | Oct 23, 2023 | IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. ... |
| CVE-2023-43045 | HIGH | 7.5 | 0.7% | Oct 23, 2023 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized action... |
| CVE-2023-46122 | HIGH | 7.1 | 0.3% | Oct 23, 2023 | sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of... |
| CVE-2023-43066 | HIGH | 7.8 | 0.2% | Oct 23, 2023 | Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local atta... |
| CVE-2023-43074 | HIGH | 7.5 | 0.5% | Oct 23, 2023 | Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially... |
| CVE-2023-42295 | HIGH | 8.8 | 0.9% | Oct 23, 2023 | An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service... |
| CVE-2023-28797 | HIGH | 7.3 | 0.2% | Oct 23, 2023 | Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk.... |
| CVE-2023-28796 | HIGH | 7.8 | 0.2% | Oct 23, 2023 | Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injectio... |
| CVE-2023-28795 | HIGH | 7.8 | 0.1% | Oct 23, 2023 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now