2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45698 | MEDIUM | 6.1 | 0.3% | Feb 10, 2024 | Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropria... |
| CVE-2023-45696 | HIGH | 7.5 | 0.4% | Feb 10, 2024 | Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allow... |
| CVE-2023-28077 | MEDIUM | 4.4 | 0.2% | Feb 10, 2024 | Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary informa... |
| CVE-2023-6935 | MEDIUM | 5.9 | 0.5% | Feb 9, 2024 | wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher styl... |
| CVE-2023-45718 | HIGH | 7.5 | 0.4% | Feb 9, 2024 | Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persi... |
| CVE-2023-45716 | MEDIUM | 4.1 | 0.1% | Feb 9, 2024 | Sametime is impacted by sensitive information passed in URL. |
| CVE-2023-50349 | HIGH | 8.8 | 0.2% | Feb 9, 2024 | Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy applica... |
| CVE-2023-50386 | HIGH | 8.8 | 83.8% | Feb 9, 2024 | Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Fu... |
| CVE-2023-50298 | HIGH | 7.5 | 1.6% | Feb 9, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: ... |
| CVE-2023-50292 | HIGH | 7.5 | 3.0% | Feb 9, 2024 | Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerabil... |
| CVE-2023-50291 | HIGH | 7.5 | 3.3% | Feb 9, 2024 | Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8... |
| CVE-2023-6677 | CRITICAL | 9.8 | 0.5% | Feb 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Te... |
| CVE-2023-6724 | HIGH | 8.8 | 0.6% | Feb 9, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Lim... |
| CVE-2023-6716 | — | — | — | Feb 9, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. All references and descriptions in this record have been remov... |
| CVE-2023-50026 | CRITICAL | 9.8 | 0.6% | Feb 9, 2024 | SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop vers... |
| CVE-2023-46350 | CRITICAL | 9.8 | 0.6% | Feb 9, 2024 | SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for... |
| CVE-2023-39683 | MEDIUM | 6.1 | 0.5% | Feb 9, 2024 | Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary c... |
| CVE-2023-31506 | MEDIUM | 5.4 | 1.0% | Feb 9, 2024 | A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to ... |
| CVE-2023-51761 | HIGH | 8.1 | 0.7% | Feb 9, 2024 | In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass a... |
| CVE-2023-49716 | CRITICAL | 9.8 | 0.6% | Feb 9, 2024 | In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbit... |
| CVE-2023-46687 | CRITICAL | 9.8 | 0.9% | Feb 9, 2024 | In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execu... |
| CVE-2023-43609 | CRITICAL | 9.1 | 0.5% | Feb 9, 2024 | In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain a... |
| CVE-2023-45191 | HIGH | 7.5 | 0.7% | Feb 9, 2024 | IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a rem... |
| CVE-2023-45190 | MEDIUM | 6.1 | 0.3% | Feb 9, 2024 | IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper valida... |
| CVE-2023-45187 | HIGH | 8.8 | 0.4% | Feb 9, 2024 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now