2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3701 | HIGH | 8.8 | 0.6% | Oct 4, 2023 | Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerabili... |
| CVE-2023-3512 | HIGH | 7.5 | 0.6% | Oct 4, 2023 | Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploit... |
| CVE-2023-37995 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ... |
| CVE-2023-2422 | HIGH | 7.1 | 0.4% | Oct 4, 2023 | A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does ... |
| CVE-2023-25980 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Re... |
| CVE-2023-25788 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Saphali Saphali Woocommerce Lite plugin <= 1.8.13 versions. |
| CVE-2023-25489 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 ver... |
| CVE-2023-1584 | HIGH | 7.5 | 1.0% | Oct 4, 2023 | A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an inse... |
| CVE-2023-5377 | HIGH | 7.1 | 0.3% | Oct 4, 2023 | Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV. |
| CVE-2023-5369 | HIGH | 7.1 | 0.2% | Oct 4, 2023 | Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input... |
| CVE-2023-30738 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro,... |
| CVE-2023-30733 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attac... |
| CVE-2023-30727 | HIGH | 7.5 | 0.4% | Oct 4, 2023 | Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi an... |
| CVE-2023-30692 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch pr... |
| CVE-2023-30690 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileg... |
| CVE-2023-43176 | HIGH | 8.8 | 1.7% | Oct 3, 2023 | A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplyi... |
| CVE-2023-43976 | HIGH | 8.1 | 0.5% | Oct 3, 2023 | An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race conditio... |
| CVE-2023-5255 | HIGH | 7.5 | 0.4% | Oct 3, 2023 | For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates fro... |
| CVE-2023-4911 | HIGH | 7.8 | 78.6% | Oct 3, 2023 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environ... |
| CVE-2023-4817 | HIGH | 8.8 | 0.6% | Oct 3, 2023 | This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the uploa... |
| CVE-2023-4884 | HIGH | 7.5 | 0.4% | Oct 3, 2023 | An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to t... |
| CVE-2023-4883 | HIGH | 7.5 | 0.5% | Oct 3, 2023 | Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the corr... |
| CVE-2023-4882 | HIGH | 7.5 | 0.5% | Oct 3, 2023 | DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could... |
| CVE-2023-4929 | HIGH | 8.8 | 0.3% | Oct 3, 2023 | All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. ... |
| CVE-2023-41693 | HIGH | 8.8 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview MyCryptoCheckout plugin <= 2.125 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now