2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42016 | MEDIUM | 4.3 | 0.3% | Feb 9, 2024 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure... |
| CVE-2023-32341 | MEDIUM | 6.5 | 0.6% | Feb 9, 2024 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cau... |
| CVE-2023-51630 | MEDIUM | 6.1 | 1.7% | Feb 8, 2024 | Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote... |
| CVE-2023-47132 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API ... |
| CVE-2023-47131 | HIGH | 7.5 | 0.5% | Feb 8, 2024 | The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file. |
| CVE-2023-40264 | MEDIUM | 4.3 | 0.5% | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path t... |
| CVE-2023-40263 | HIGH | 8.8 | 1.2% | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated comman... |
| CVE-2023-40262 | MEDIUM | 6.1 | 0.3% | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stor... |
| CVE-2023-49101 | MEDIUM | 6.1 | 0.2% | Feb 8, 2024 | WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against ... |
| CVE-2023-40266 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path tra... |
| CVE-2023-40265 | HIGH | 8.8 | 0.9% | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenti... |
| CVE-2023-27001 | HIGH | 8.8 | 0.9% | Feb 8, 2024 | An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the... |
| CVE-2023-25365 | HIGH | 7.8 | 0.4% | Feb 8, 2024 | Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the ... |
| CVE-2023-50061 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionD... |
| CVE-2023-42282 | CRITICAL | 9.8 | 1.6% | Feb 8, 2024 | The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categ... |
| CVE-2023-47020 | HIGH | 8.8 | 0.3% | Feb 8, 2024 | Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by... |
| CVE-2023-7169 | MEDIUM | 5.5 | 0.2% | Feb 8, 2024 | Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.... |
| CVE-2023-6564 | MEDIUM | 6.5 | 0.4% | Feb 8, 2024 | An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In project... |
| CVE-2023-6519 | HIGH | 7.5 | 0.5% | Feb 8, 2024 | Exposure of Data Element to Wrong Session vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Wit... |
| CVE-2023-6518 | HIGH | 7.5 | 0.4% | Feb 8, 2024 | Plaintext Storage of a Password vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Exe... |
| CVE-2023-6517 | HIGH | 7.5 | 0.5% | Feb 8, 2024 | Exposure of Sensitive Information Due to Incompatible Policies vulnerability in Mia Technology Inc. MİA-MED allows Colle... |
| CVE-2023-6515 | HIGH | 8.8 | 0.6% | Feb 8, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abus... |
| CVE-2023-5665 | MEDIUM | 5.4 | 0.5% | Feb 8, 2024 | The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc... |
| CVE-2023-47798 | MEDIUM | 4.6 | 0.3% | Feb 8, 2024 | Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pa... |
| CVE-2023-48974 | CRITICAL | 9.6 | 3.0% | Feb 8, 2024 | Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now