2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26300 | HIGH | 7.8 | 0.2% | Oct 18, 2023 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow e... |
| CVE-2023-45912 | HIGH | 7.5 | 0.6% | Oct 18, 2023 | WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers ... |
| CVE-2023-30911 | HIGH | 7.5 | 0.5% | Oct 18, 2023 | HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service. |
| CVE-2023-46009 | HIGH | 7.8 | 0.3% | Oct 18, 2023 | gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c. |
| CVE-2023-45383 | HIGH | 7.5 | 0.6% | Oct 18, 2023 | In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest c... |
| CVE-2023-43250 | HIGH | 7.8 | 0.6% | Oct 18, 2023 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attacker... |
| CVE-2023-46004 | HIGH | 7.2 | 0.7% | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function. |
| CVE-2023-45727 | HIGH | 7.5 | 3.5% | Oct 18, 2023 | Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail S... |
| CVE-2023-5632 | HIGH | 7.5 | 0.7% | Oct 18, 2023 | In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data c... |
| CVE-2023-42319 | HIGH | 7.5 | 0.9% | Oct 18, 2023 | Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of servi... |
| CVE-2023-39331 | HIGH | 7.5 | 1.3% | Oct 18, 2023 | A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path travers... |
| CVE-2023-38552 | HIGH | 7.5 | 1.1% | Oct 18, 2023 | When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can inter... |
| CVE-2023-5626 | HIGH | 8.8 | 0.3% | Oct 18, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16. |
| CVE-2023-5552 | HIGH | 7.5 | 0.5% | Oct 18, 2023 | A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to ... |
| CVE-2023-45811 | HIGH | 7.8 | 0.4% | Oct 17, 2023 | Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions... |
| CVE-2023-45810 | HIGH | 7.5 | 0.5% | Oct 17, 2023 | OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected ver... |
| CVE-2023-42507 | HIGH | 7.8 | 0.2% | Oct 17, 2023 | Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is expl... |
| CVE-2023-42506 | HIGH | 7.8 | 0.2% | Oct 17, 2023 | Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and ea... |
| CVE-2023-41715 | HIGH | 8.8 | 0.7% | Oct 17, 2023 | SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to el... |
| CVE-2023-41713 | HIGH | 7.5 | 0.6% | Oct 17, 2023 | SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. |
| CVE-2023-36321 | HIGH | 7.5 | 0.9% | Oct 17, 2023 | Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component ... |
| CVE-2023-41631 | HIGH | 8.8 | 1.1% | Oct 17, 2023 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload funct... |
| CVE-2023-41629 | HIGH | 7.5 | 0.7% | Oct 17, 2023 | A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path t... |
| CVE-2023-22108 | HIGH | 7.5 | 0.6% | Oct 17, 2023 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2023-22102 | HIGH | 8.3 | 0.9% | Oct 17, 2023 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now