2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42456 | HIGH | 8.1 | 0.6% | Sep 21, 2023 | Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo att... |
| CVE-2023-42457 | HIGH | 7.5 | 0.8% | Sep 21, 2023 | plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and ... |
| CVE-2023-43637 | HIGH | 7.8 | 0.1% | Sep 21, 2023 | Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the las... |
| CVE-2023-43634 | HIGH | 8.8 | 0.2% | Sep 21, 2023 | When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous proje... |
| CVE-2023-43633 | HIGH | 8.8 | 0.2% | Sep 21, 2023 | On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the f... |
| CVE-2023-43631 | HIGH | 8.8 | 0.2% | Sep 21, 2023 | On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is pr... |
| CVE-2023-43274 | HIGH | 7.5 | 0.6% | Sep 21, 2023 | Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter. |
| CVE-2023-4152 | HIGH | 7.5 | 0.7% | Sep 21, 2023 | Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal ... |
| CVE-2023-43669 | HIGH | 7.5 | 1.6% | Sep 21, 2023 | The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consum... |
| CVE-2023-37279 | HIGH | 7.5 | 0.8% | Sep 20, 2023 | Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can s... |
| CVE-2023-42321 | HIGH | 8.8 | 0.4% | Sep 20, 2023 | Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary co... |
| CVE-2023-39677 | HIGH | 7.5 | 30.8% | Sep 20, 2023 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInf... |
| CVE-2023-43138 | HIGH | 8.8 | 2.1% | Sep 20, 2023 | TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT ru... |
| CVE-2023-43137 | HIGH | 8.8 | 2.1% | Sep 20, 2023 | TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rul... |
| CVE-2023-42335 | HIGH | 8.8 | 1.1% | Sep 20, 2023 | Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to exec... |
| CVE-2023-42331 | HIGH | 8.8 | 1.2% | Sep 20, 2023 | A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.... |
| CVE-2023-42147 | HIGH | 7.5 | 0.4% | Sep 20, 2023 | An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component. |
| CVE-2023-41484 | HIGH | 8.1 | 0.6% | Sep 20, 2023 | An issue in cimg.eu Cimg Library v2.9.3 allows an attacker to obtain sensitive information via a crafted JPEG file. |
| CVE-2023-37410 | HIGH | 7.8 | 0.2% | Sep 20, 2023 | IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM... |
| CVE-2023-43500 | HIGH | 8.8 | 0.4% | Sep 20, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta... |
| CVE-2023-43498 | HIGH | 8.1 | 0.8% | Sep 20, 2023 | In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates tem... |
| CVE-2023-43497 | HIGH | 8.1 | 0.8% | Sep 20, 2023 | In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates t... |
| CVE-2023-43496 | HIGH | 8.8 | 0.9% | Sep 20, 2023 | Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the d... |
| CVE-2023-42660 | HIGH | 8.8 | 0.6% | Sep 20, 2023 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ... |
| CVE-2023-40043 | HIGH | 7.2 | 0.6% | Sep 20, 2023 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now