2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50935 | MEDIUM | 6.5 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker ... |
| CVE-2023-50934 | MEDIUM | 5.3 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when co... |
| CVE-2023-50328 | MEDIUM | 5.3 | 0.5% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM... |
| CVE-2023-48793 | CRITICAL | 9.8 | 7.0% | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. |
| CVE-2023-48792 | CRITICAL | 9.8 | 7.0% | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. |
| CVE-2023-46344 | MEDIUM | 5.4 | 0.6% | Feb 2, 2024 | A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an att... |
| CVE-2023-32333 | CRITICAL | 9.8 | 0.5% | Feb 2, 2024 | IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access con... |
| CVE-2023-50940 | CRITICAL | 9.8 | 0.5% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privi... |
| CVE-2023-50937 | HIGH | 7.5 | 0.3% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt... |
| CVE-2023-50936 | HIGH | 8.8 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impers... |
| CVE-2023-50933 | MEDIUM | 6.1 | 0.4% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which... |
| CVE-2023-50327 | MEDIUM | 5.3 | 0.5% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized fil... |
| CVE-2023-50326 | HIGH | 7.5 | 0.7% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute for... |
| CVE-2023-50939 | HIGH | 7.5 | 0.3% | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt... |
| CVE-2023-6221 | MEDIUM | 6.5 | 0.6% | Feb 1, 2024 | The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the prog... |
| CVE-2023-49617 | CRITICAL | 9.1 | 0.8% | Feb 1, 2024 | The MachineSense application programmable interface (API) is improperly protected and can be accessed without authe... |
| CVE-2023-49610 | HIGH | 8.1 | 0.4% | Feb 1, 2024 | MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on a... |
| CVE-2023-49115 | HIGH | 7.5 | 0.6% | Feb 1, 2024 | MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by u... |
| CVE-2023-47867 | HIGH | 8.8 | 0.4% | Feb 1, 2024 | MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect... |
| CVE-2023-46706 | CRITICAL | 9.8 | 0.7% | Feb 1, 2024 | Multiple MachineSense devices have credentials unable to be changed by the user or administrator. |
| CVE-2023-36496 | HIGH | 8.8 | 0.5% | Feb 1, 2024 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their... |
| CVE-2023-4472 | CRITICAL | 9.8 | 0.6% | Feb 1, 2024 | Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled t... |
| CVE-2023-47257 | HIGH | 8.1 | 1.0% | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted... |
| CVE-2023-47256 | MEDIUM | 5.5 | 0.4% | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of ... |
| CVE-2023-5841 | CRITICAL | 9.1 | 1.3% | Feb 1, 2024 | Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy S... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now