2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44155 | HIGH | 7.5 | 0.7% | Sep 27, 2023 | Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Wind... |
| CVE-2023-44154 | HIGH | 8.1 | 0.6% | Sep 27, 2023 | Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac... |
| CVE-2023-44153 | HIGH | 7.5 | 0.3% | Sep 27, 2023 | Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are... |
| CVE-2023-44125 | HIGH | 7.8 | 0.1% | Sep 27, 2023 | The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft... |
| CVE-2023-44123 | HIGH | 7.8 | 0.1% | Sep 27, 2023 | The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/... |
| CVE-2023-44122 | HIGH | 7.8 | 0.1% | Sep 27, 2023 | The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreenset... |
| CVE-2023-44044 | HIGH | 7.2 | 0.9% | Sep 27, 2023 | Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /a... |
| CVE-2023-43856 | HIGH | 7.5 | 0.8% | Sep 27, 2023 | Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateContr... |
| CVE-2023-43825 | HIGH | 7.8 | 0.3% | Sep 27, 2023 | Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arb... |
| CVE-2023-43646 | HIGH | 7.5 | 1.1% | Sep 27, 2023 | get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versio... |
| CVE-2023-43610 | HIGH | 8.8 | 0.9% | Sep 27, 2023 | SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with edit... |
| CVE-2023-43381 | HIGH | 7.5 | 1.0% | Sep 27, 2023 | SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id... |
| CVE-2023-42820 | HIGH | 8.2 | 5.4% | Sep 27, 2023 | JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, pote... |
| CVE-2023-42819 | HIGH | 8.8 | 1.9% | Sep 27, 2023 | JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system.... |
| CVE-2023-42487 | HIGH | 7.5 | 0.9% | Sep 27, 2023 | Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2023-42486 | HIGH | 7.8 | 0.2% | Sep 27, 2023 | Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges. |
| CVE-2023-42460 | HIGH | 7.5 | 0.6% | Sep 27, 2023 | Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is... |
| CVE-2023-41995 | HIGH | 7.8 | 0.3% | Sep 27, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS... |
| CVE-2023-41984 | HIGH | 7.8 | 0.5% | Sep 27, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and ... |
| CVE-2023-41333 | HIGH | 8.1 | 0.4% | Sep 27, 2023 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability ... |
| CVE-2023-41326 | HIGH | 8.8 | 31.2% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-41324 | HIGH | 8.8 | 0.7% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-41322 | HIGH | 8.8 | 0.7% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-41309 | HIGH | 7.5 | 0.5% | Sep 27, 2023 | Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability ma... |
| CVE-2023-41308 | HIGH | 7.5 | 0.5% | Sep 27, 2023 | Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now