2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46096 | MEDIUM | 6.5 | 0.3% | Nov 14, 2023 | A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does ... |
| CVE-2023-44322 | MEDIUM | 5.9 | 0.9% | Nov 14, 2023 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM... |
| CVE-2023-44321 | MEDIUM | 6.5 | 1.0% | Nov 14, 2023 | Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web ... |
| CVE-2023-44320 | MEDIUM | 4.3 | 0.6% | Nov 14, 2023 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDC... |
| CVE-2023-44319 | MEDIUM | 4.9 | 0.4% | Nov 14, 2023 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM... |
| CVE-2023-44318 | MEDIUM | 4.9 | 0.7% | Nov 14, 2023 | Affected devices use a hardcoded key to obfuscate the configuration backup that an administrator can export from the dev... |
| CVE-2023-43505 | MEDIUM | 6.5 | 0.5% | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SM... |
| CVE-2023-45881 | MEDIUM | 6.1 | 0.5% | Nov 14, 2023 | GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resu... |
| CVE-2023-45879 | MEDIUM | 5.4 | 0.5% | Nov 14, 2023 | GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component. |
| CVE-2023-43901 | MEDIUM | 5.9 | 0.5% | Nov 14, 2023 | Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrar... |
| CVE-2023-43900 | MEDIUM | 6.5 | 0.6% | Nov 14, 2023 | Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application c... |
| CVE-2023-6006 | MEDIUM | 6.7 | 0.4% | Nov 14, 2023 | This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. A... |
| CVE-2023-42327 | MEDIUM | 5.4 | 55.4% | Nov 14, 2023 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a cr... |
| CVE-2023-42325 | MEDIUM | 5.4 | 57.9% | Nov 14, 2023 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a cr... |
| CVE-2023-31754 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin pan... |
| CVE-2023-46446 | MEDIUM | 6.8 | 0.9% | Nov 14, 2023 | An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet inject... |
| CVE-2023-46445 | MEDIUM | 5.9 | 0.6% | Nov 14, 2023 | An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-mi... |
| CVE-2023-47628 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default s... |
| CVE-2023-42480 | MEDIUM | 5.3 | 0.5% | Nov 14, 2023 | The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functional... |
| CVE-2023-41366 | MEDIUM | 5.3 | 0.6% | Nov 14, 2023 | Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.... |
| CVE-2023-47684 | MEDIUM | 6.1 | 0.8% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions. |
| CVE-2023-47680 | MEDIUM | 5.4 | 0.4% | Nov 14, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Qode Interactive Qi Addons For Elementor plugin ... |
| CVE-2023-47673 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Stefano Ottolenghi Post Pay Counter plugin <= 2.784 versio... |
| CVE-2023-47665 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in edward_plainview Plainview Protect Passwords plugin <= 1.4... |
| CVE-2023-47662 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GoldBroker.Com Live Gold Price & Silver Price Charts W... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now