2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38615 | HIGH | 7.8 | 0.3% | Sep 27, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to exe... |
| CVE-2023-35793 | HIGH | 8.8 | 0.9% | Sep 27, 2023 | An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vuln... |
| CVE-2023-35074 | HIGH | 8.8 | 1.5% | Sep 27, 2023 | The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and... |
| CVE-2023-32541 | HIGH | 7.8 | 0.7% | Sep 27, 2023 | A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially ... |
| CVE-2023-32396 | HIGH | 7.8 | 0.3% | Sep 27, 2023 | This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 1... |
| CVE-2023-32377 | HIGH | 7.8 | 0.3% | Sep 27, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may ... |
| CVE-2023-2315 | HIGH | 8.8 | 0.8% | Sep 27, 2023 | Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the ... |
| CVE-2023-28055 | HIGH | 8.8 | 0.3% | Sep 27, 2023 | Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated at... |
| CVE-2023-0456 | HIGH | 7.5 | 0.6% | Sep 27, 2023 | A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token fro... |
| CVE-2023-4259 | HIGH | 8.8 | 0.7% | Sep 26, 2023 | Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code. |
| CVE-2023-43278 | HIGH | 8.8 | 0.3% | Sep 25, 2023 | A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an ad... |
| CVE-2023-38907 | HIGH | 7.5 | 0.7% | Sep 25, 2023 | An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a... |
| CVE-2023-42753 | HIGH | 7.8 | 0.5% | Sep 25, 2023 | An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to ... |
| CVE-2023-43642 | HIGH | 7.5 | 1.0% | Sep 25, 2023 | snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream ... |
| CVE-2023-40581 | HIGH | 7.8 | 1.3% | Sep 25, 2023 | yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to... |
| CVE-2023-4156 | HIGH | 7.1 | 0.4% | Sep 25, 2023 | A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be u... |
| CVE-2023-5165 | HIGH | 8.8 | 0.2% | Sep 25, 2023 | Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via t... |
| CVE-2023-5156 | HIGH | 7.5 | 1.3% | Sep 25, 2023 | A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which ... |
| CVE-2023-4300 | HIGH | 7.2 | 1.7% | Sep 25, 2023 | The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing ... |
| CVE-2023-4238 | HIGH | 7.2 | 1.3% | Sep 25, 2023 | The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could all... |
| CVE-2023-43382 | HIGH | 8.8 | 1.5% | Sep 25, 2023 | Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via... |
| CVE-2023-3664 | HIGH | 7.2 | 0.6% | Sep 25, 2023 | The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site a... |
| CVE-2023-3550 | HIGH | 7.3 | 1.2% | Sep 25, 2023 | Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML f... |
| CVE-2023-3547 | HIGH | 8.8 | 0.3% | Sep 25, 2023 | The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several action... |
| CVE-2023-32653 | HIGH | 8.8 | 1.0% | Sep 25, 2023 | An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A spe... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now