2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-7004MEDIUM6.5The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected devic...
CVE-2023-7003MEDIUM6.8The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, a...
CVE-2023-6960HIGH7.5TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended ...
CVE-2023-47699MEDIUM6.1IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2023-47147MEDIUM5.3IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. ...
CVE-2023-46181LOW3.3IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the...
CVE-2023-51522HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member S...
CVE-2023-51369HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Cus...
CVE-2023-50898HIGH8.8Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.
CVE-2023-50886HIGH8Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal P...
CVE-2023-47162MEDIUM6.1IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2023-46182MEDIUM5.4IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2023-46179MEDIUM4.3IBM Sterling Secure Proxy 6.0.3 and 6.1.0 does not set the secure attribute on authorization tokens or session cookies. ...
CVE-2023-51525MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Veribo, Roland Murg WP Simple Booking Calendar.This issue affects WP ...
CVE-2023-50861HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).Th...
CVE-2023-6725MEDIUM5.5An access-control flaw was found in the OpenStack Designate component where private configuration information including ...
CVE-2023-50677HIGH8.8An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file param...
CVE-2023-42286CRITICAL9.8There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execu...
CVE-2023-42938HIGH7.8A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker ma...
CVE-2023-43490MEDIUM5.3Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a...
CVE-2023-39368MEDIUM6.5Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to pot...
CVE-2023-38575MEDIUM5.5Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized...
CVE-2023-35191MEDIUM6.8Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially ena...
CVE-2023-32666HIGH7.2On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when us...
CVE-2023-32633MEDIUM6.7Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated u...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now