2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4920 | HIGH | 8.8 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-40361 | HIGH | 7.8 | 0.3% | Oct 20, 2023 | SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker ... |
| CVE-2023-46277 | HIGH | 7.8 | 0.3% | Oct 20, 2023 | please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOC... |
| CVE-2023-34052 | HIGH | 7.8 | 0.2% | Oct 20, 2023 | VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative acce... |
| CVE-2023-44385 | HIGH | 8.8 | 0.3% | Oct 19, 2023 | The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. A... |
| CVE-2023-43345 | HIGH | 8.6 | 0.4% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co... |
| CVE-2023-41899 | HIGH | 7.2 | 0.5% | Oct 19, 2023 | Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a parti... |
| CVE-2023-41898 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is... |
| CVE-2023-44690 | HIGH | 7.5 | 0.2% | Oct 19, 2023 | Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py |
| CVE-2023-45823 | HIGH | 7.5 | 0.6% | Oct 19, 2023 | Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for... |
| CVE-2023-30132 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptog... |
| CVE-2023-27795 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key. |
| CVE-2023-27793 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak ... |
| CVE-2023-27792 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions ... |
| CVE-2023-40145 | HIGH | 8.8 | 1.2% | Oct 19, 2023 | In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to th... |
| CVE-2023-27791 | HIGH | 8.1 | 0.7% | Oct 19, 2023 | An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG. |
| CVE-2023-42435 | HIGH | 8.8 | 0.2% | Oct 19, 2023 | The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to pe... |
| CVE-2023-41089 | HIGH | 8.8 | 0.5% | Oct 19, 2023 | The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to ... |
| CVE-2023-5059 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Santesoft Sante FFT Imaging lacks proper validation of user-supplied data when parsing DICOM files. This could lead... |
| CVE-2023-39431 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an ... |
| CVE-2023-38128 | HIGH | 7.8 | 0.7% | Oct 19, 2023 | An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specia... |
| CVE-2023-38127 | HIGH | 7.8 | 0.6% | Oct 19, 2023 | An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted docum... |
| CVE-2023-35986 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a sta... |
| CVE-2023-34366 | HIGH | 7.8 | 0.6% | Oct 19, 2023 | A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A special... |
| CVE-2023-45277 | HIGH | 7.5 | 1.0% | Oct 19, 2023 | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of th... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now