2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28793 | HIGH | 7.8 | 0.3% | Oct 23, 2023 | Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. Th... |
| CVE-2023-5246 | HIGH | 8.8 | 0.8% | Oct 23, 2023 | Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074,... |
| CVE-2023-43622 | HIGH | 7.5 | 70.6% | Oct 23, 2023 | An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection... |
| CVE-2023-31122 | HIGH | 7.5 | 3.0% | Oct 23, 2023 | Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.5... |
| CVE-2023-46324 | HIGH | 7.5 | 0.4% | Oct 23, 2023 | pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may... |
| CVE-2023-46319 | HIGH | 7.5 | 0.5% | Oct 23, 2023 | WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassi... |
| CVE-2023-46317 | HIGH | 7.5 | 0.6% | Oct 22, 2023 | Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers. |
| CVE-2023-46315 | HIGH | 7.5 | 0.6% | Oct 22, 2023 | The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-... |
| CVE-2023-46095 | HIGH | 8.8 | 0.2% | Oct 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions. |
| CVE-2023-46089 | HIGH | 8.8 | 0.2% | Oct 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions. |
| CVE-2023-46085 | HIGH | 8.8 | 0.2% | Oct 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions. |
| CVE-2023-46303 | HIGH | 7.5 | 1.4% | Oct 22, 2023 | link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources ou... |
| CVE-2023-46298 | HIGH | 7.5 | 1.3% | Oct 22, 2023 | Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached ... |
| CVE-2023-38276 | HIGH | 7.5 | 0.4% | Oct 22, 2023 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid... |
| CVE-2023-38275 | HIGH | 7.5 | 0.4% | Oct 22, 2023 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to ... |
| CVE-2023-46078 | HIGH | 8.8 | 0.2% | Oct 21, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in PluginEver WC Serial Numbers plugin <= 1.6.3 versions. |
| CVE-2023-46067 | HIGH | 8.8 | 0.2% | Oct 21, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions. |
| CVE-2023-46055 | HIGH | 8.8 | 1.2% | Oct 21, 2023 | An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a cra... |
| CVE-2023-5132 | HIGH | 7.5 | 0.6% | Oct 21, 2023 | The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit... |
| CVE-2023-38193 | HIGH | 8.8 | 1.3% | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command l... |
| CVE-2023-38190 | HIGH | 8.8 | 0.7% | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter. |
| CVE-2023-45682 | HIGH | 7.1 | 0.6% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun... |
| CVE-2023-45681 | HIGH | 7.8 | 0.5% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory writ... |
| CVE-2023-45679 | HIGH | 7.8 | 0.5% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allo... |
| CVE-2023-45678 | HIGH | 7.8 | 0.7% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buff... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now