2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23651 | HIGH | 8.8 | 0.6% | Oct 12, 2023 | Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions. |
| CVE-2023-45047 | HIGH | 8.8 | 0.2% | Oct 12, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions. |
| CVE-2023-32724 | HIGH | 8.8 | 0.6% | Oct 12, 2023 | Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory ... |
| CVE-2023-32722 | HIGH | 7.8 | 0.7% | Oct 12, 2023 | The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open. |
| CVE-2023-40829 | HIGH | 7.5 | 0.5% | Oct 12, 2023 | There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5... |
| CVE-2023-1943 | HIGH | 8.8 | 0.6% | Oct 12, 2023 | Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode. |
| CVE-2023-5476 | HIGH | 8.8 | 0.9% | Oct 11, 2023 | Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit... |
| CVE-2023-5474 | HIGH | 8.8 | 0.9% | Oct 11, 2023 | Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to en... |
| CVE-2023-5218 | HIGH | 8.8 | 1.3% | Oct 11, 2023 | Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploi... |
| CVE-2023-39325 | HIGH | 7.5 | 3.8% | Oct 11, 2023 | A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource... |
| CVE-2023-44186 | HIGH | 7.5 | 0.5% | Oct 11, 2023 | An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Jun... |
| CVE-2023-3781 | HIGH | 7.8 | 0.1% | Oct 11, 2023 | there is a possible use-after-free write due to improper locking. This could lead to local escalation of privilege with ... |
| CVE-2023-5535 | HIGH | 7.8 | 0.5% | Oct 11, 2023 | Use After Free in GitHub repository vim/vim prior to v9.0.2010. |
| CVE-2023-43661 | HIGH | 8.8 | 46.9% | Oct 11, 2023 | Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to crea... |
| CVE-2023-40142 | HIGH | 7.8 | 0.1% | Oct 11, 2023 | In TBD of TBD, there is a possible way to bypass carrier restrictions due to a logic error in the code. This could lead ... |
| CVE-2023-40141 | HIGH | 7.8 | 0.1% | Oct 11, 2023 | In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a missing bounds check... |
| CVE-2023-35661 | HIGH | 7.5 | 0.4% | Oct 11, 2023 | In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds che... |
| CVE-2023-35652 | HIGH | 7.5 | 0.3% | Oct 11, 2023 | In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a... |
| CVE-2023-35649 | HIGH | 7.2 | 0.4% | Oct 11, 2023 | In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This ... |
| CVE-2023-44961 | HIGH | 7.5 | 1.1% | Oct 11, 2023 | SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive i... |
| CVE-2023-38817 | HIGH | 7.8 | 0.5% | Oct 11, 2023 | An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to th... |
| CVE-2023-43960 | HIGH | 8.8 | 1.1% | Oct 11, 2023 | An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in... |
| CVE-2023-23930 | HIGH | 7.2 | 0.9% | Oct 11, 2023 | vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known se... |
| CVE-2023-35194 | HIGH | 8.8 | 5.6% | Oct 11, 2023 | An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v... |
| CVE-2023-35193 | HIGH | 8.8 | 5.6% | Oct 11, 2023 | An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now