2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6565 | MEDIUM | 5.9 | 0.6% | Feb 29, 2024 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2023-6247 | MEDIUM | 6.5 | 0.8% | Feb 29, 2024 | The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which woul... |
| CVE-2023-51835 | MEDIUM | 6.8 | 7.3% | Feb 29, 2024 | An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping... |
| CVE-2023-51779 | HIGH | 7 | 0.3% | Feb 29, 2024 | bt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_s... |
| CVE-2023-51775 | MEDIUM | 6.5 | 0.9% | Feb 29, 2024 | The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p... |
| CVE-2023-51774 | HIGH | 8.4 | 0.2% | Feb 29, 2024 | The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confus... |
| CVE-2023-51773 | CRITICAL | 9.1 | 1.1% | Feb 29, 2024 | BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c. |
| CVE-2023-50658 | HIGH | 7.5 | 0.8% | Feb 29, 2024 | The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2... |
| CVE-2023-50437 | HIGH | 8.6 | 0.7% | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/defau... |
| CVE-2023-50436 | MEDIUM | 5.3 | 0.2% | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the ... |
| CVE-2023-49932 | MEDIUM | 5.4 | 0.5% | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions. |
| CVE-2023-49931 | CRITICAL | 9.8 | 0.9% | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted... |
| CVE-2023-49930 | CRITICAL | 9.8 | 0.9% | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. |
| CVE-2023-49337 | MEDIUM | 4.8 | 0.5% | Feb 29, 2024 | Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier a... |
| CVE-2023-48653 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/de... |
| CVE-2023-48651 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/subm... |
| CVE-2023-48650 | MEDIUM | 4.8 | 0.5% | Feb 29, 2024 | Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Prese... |
| CVE-2023-47634 | LOW | 3.1 | 0.4% | Feb 29, 2024 | Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.2... |
| CVE-2023-45874 | MEDIUM | 4.3 | 0.8% | Feb 29, 2024 | An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader... |
| CVE-2023-44347 | MEDIUM | 5.5 | 0.3% | Feb 29, 2024 | Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulne... |
| CVE-2023-44346 | MEDIUM | 5.5 | 0.3% | Feb 29, 2024 | Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil... |
| CVE-2023-44345 | MEDIUM | 5.5 | 0.3% | Feb 29, 2024 | Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vuln... |
| CVE-2023-44344 | MEDIUM | 5.5 | 0.3% | Feb 29, 2024 | Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil... |
| CVE-2023-44343 | MEDIUM | 5.5 | 0.3% | Feb 29, 2024 | Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil... |
| CVE-2023-44342 | MEDIUM | 5.5 | 0.3% | Feb 29, 2024 | Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now