2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36618 | HIGH | 8.8 | 3.4% | Oct 4, 2023 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-... |
| CVE-2023-44209 | HIGH | 7.8 | 0.3% | Oct 4, 2023 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec... |
| CVE-2023-42809 | HIGH | 8.8 | 1.0% | Oct 4, 2023 | Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received fr... |
| CVE-2023-42449 | HIGH | 8.1 | 0.9% | Oct 4, 2023 | Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head in... |
| CVE-2023-42824 | HIGH | 7.8 | 0.9% | Oct 4, 2023 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may ... |
| CVE-2023-42448 | HIGH | 8.1 | 0.8% | Oct 4, 2023 | Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the cont... |
| CVE-2023-39191 | HIGH | 8.2 | 0.5% | Oct 4, 2023 | An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of... |
| CVE-2023-43804 | HIGH | 8.1 | 1.2% | Oct 4, 2023 | urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or pro... |
| CVE-2023-20259 | HIGH | 7.5 | 0.6% | Oct 4, 2023 | A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, rem... |
| CVE-2023-20235 | HIGH | 8.8 | 0.5% | Oct 4, 2023 | A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastr... |
| CVE-2023-43838 | HIGH | 7.8 | 0.6% | Oct 4, 2023 | An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code ... |
| CVE-2023-4237 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the priv... |
| CVE-2023-40559 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin... |
| CVE-2023-3665 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable th... |
| CVE-2023-40561 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugi... |
| CVE-2023-27433 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery... |
| CVE-2023-25025 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ... |
| CVE-2023-1832 | HIGH | 8.1 | 0.5% | Oct 4, 2023 | An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant... |
| CVE-2023-43261 | HIGH | 7.5 | 60.2% | Oct 4, 2023 | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensiti... |
| CVE-2023-3361 | HIGH | 7.5 | 0.5% | Oct 4, 2023 | A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as... |
| CVE-2023-3038 | HIGH | 7.5 | 0.6% | Oct 4, 2023 | SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote atta... |
| CVE-2023-3037 | HIGH | 8.6 | 0.6% | Oct 4, 2023 | Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a re... |
| CVE-2023-22618 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users ... |
| CVE-2023-4997 | HIGH | 8.8 | 0.5% | Oct 4, 2023 | Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to cha... |
| CVE-2023-4586 | HIGH | 7.4 | 0.4% | Oct 4, 2023 | A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostna... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now