2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45354 | HIGH | 8.8 | 0.9% | Oct 9, 2023 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attac... |
| CVE-2023-45353 | HIGH | 8.8 | 0.7% | Oct 9, 2023 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to ... |
| CVE-2023-45352 | HIGH | 8.8 | 0.8% | Oct 9, 2023 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to ... |
| CVE-2023-45351 | HIGH | 8.8 | 1.3% | Oct 9, 2023 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.... |
| CVE-2023-45350 | HIGH | 8.8 | 0.6% | Oct 9, 2023 | Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may ... |
| CVE-2023-45349 | HIGH | 7.5 | 0.5% | Oct 9, 2023 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 M... |
| CVE-2023-40635 | HIGH | 7.8 | 0.1% | Oct 8, 2023 | In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no add... |
| CVE-2023-40634 | HIGH | 7.8 | 0.1% | Oct 8, 2023 | In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with... |
| CVE-2023-40632 | HIGH | 7.5 | 0.4% | Oct 8, 2023 | In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure... |
| CVE-2023-43615 | HIGH | 7.5 | 0.8% | Oct 7, 2023 | Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. |
| CVE-2023-36123 | HIGH | 7.8 | 0.7% | Oct 7, 2023 | Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to ex... |
| CVE-2023-44860 | HIGH | 7.5 | 19.5% | Oct 6, 2023 | An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization ... |
| CVE-2023-44061 | HIGH | 8.8 | 1.2% | Oct 6, 2023 | File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary co... |
| CVE-2023-45303 | HIGH | 8.8 | 0.9% | Oct 6, 2023 | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because A... |
| CVE-2023-45282 | HIGH | 7.5 | 0.9% | Oct 6, 2023 | In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action. |
| CVE-2023-21266 | HIGH | 7.8 | 0.1% | Oct 6, 2023 | In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a ... |
| CVE-2023-32972 | HIGH | 7.2 | 0.5% | Oct 6, 2023 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2023-32971 | HIGH | 7.2 | 0.5% | Oct 6, 2023 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2023-44243 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Dylan Blokhuis Instant CSS plugin <= 1.2.1 versions. |
| CVE-2023-44233 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.4... |
| CVE-2023-39928 | HIGH | 8.8 | 1.4% | Oct 6, 2023 | A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page ... |
| CVE-2023-44146 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Checkfront Inc. Checkfront Online Booking System plugin <= 3.6 versio... |
| CVE-2023-41950 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions... |
| CVE-2023-41801 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugi... |
| CVE-2023-41732 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Blocks plugin <= 1.0.20 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now