2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38273 | HIGH | 7.5 | 0.7% | Feb 2, 2024 | IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote ... |
| CVE-2023-47142 | HIGH | 8.8 | 0.3% | Feb 2, 2024 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization... |
| CVE-2023-6676 | HIGH | 8.8 | 0.3% | Feb 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Req... |
| CVE-2023-6675 | CRITICAL | 9.8 | 0.6% | Feb 2, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows ... |
| CVE-2023-6673 | MEDIUM | 6.1 | 0.3% | Feb 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cybe... |
| CVE-2023-6672 | MEDIUM | 5.4 | 0.3% | Feb 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cybe... |
| CVE-2023-47148 | HIGH | 7.5 | 0.6% | Feb 2, 2024 | IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive... |
| CVE-2023-47144 | MEDIUM | 6.1 | 0.3% | Feb 2, 2024 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This... |
| CVE-2023-47143 | CRITICAL | 9.8 | 0.8% | Feb 2, 2024 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, cau... |
| CVE-2023-51820 | MEDIUM | 6.8 | 0.5% | Feb 2, 2024 | An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitr... |
| CVE-2023-51072 | MEDIUM | 5.4 | 1.3% | Feb 2, 2024 | A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 a... |
| CVE-2023-50488 | CRITICAL | 9.8 | 1.2% | Feb 2, 2024 | An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code. |
| CVE-2023-39611 | HIGH | 7.5 | 0.6% | Feb 2, 2024 | An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local fi... |
| CVE-2023-48645 | HIGH | 7.8 | 0.2% | Feb 2, 2024 | An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web cent... |
| CVE-2023-49118 | MEDIUM | 5.5 | 0.1% | Feb 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read. |
| CVE-2023-45734 | HIGH | 8.8 | 0.3% | Feb 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds writ... |
| CVE-2023-43756 | MEDIUM | 5.5 | 0.1% | Feb 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read. |
| CVE-2023-46045 | HIGH | 7.8 | 0.7% | Feb 2, 2024 | Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability ma... |
| CVE-2023-38263 | HIGH | 8.8 | 0.5% | Feb 2, 2024 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to im... |
| CVE-2023-38020 | MEDIUM | 4.3 | 0.4% | Feb 2, 2024 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files... |
| CVE-2023-38019 | MEDIUM | 6.5 | 1.0% | Feb 2, 2024 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An att... |
| CVE-2023-46159 | MEDIUM | 6.5 | 0.7% | Feb 2, 2024 | IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service f... |
| CVE-2023-50962 | HIGH | 7.5 | 0.3% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mec... |
| CVE-2023-50941 | MEDIUM | 5.4 | 0.3% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain acc... |
| CVE-2023-50938 | MEDIUM | 4.3 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now