2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4936 | MEDIUM | 6.7 | 0.2% | Oct 11, 2023 | It is possible to sideload a compromised DLL during the installation at elevated privilege. |
| CVE-2023-34354 | MEDIUM | 5.4 | 0.8% | Oct 11, 2023 | A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 ... |
| CVE-2023-4957 | MEDIUM | 4.3 | 0.3% | Oct 11, 2023 | A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulne... |
| CVE-2023-45396 | MEDIUM | 6.5 | 0.4% | Oct 11, 2023 | An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter... |
| CVE-2023-37538 | MEDIUM | 6.1 | 0.4% | Oct 11, 2023 | HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In... |
| CVE-2023-44110 | MEDIUM | 4.3 | 0.2% | Oct 11, 2023 | Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availabi... |
| CVE-2023-44102 | MEDIUM | 5.3 | 0.4% | Oct 11, 2023 | Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cau... |
| CVE-2023-41304 | MEDIUM | 5.3 | 0.3% | Oct 11, 2023 | Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the si... |
| CVE-2023-38217 | MEDIUM | 5.5 | 0.4% | Oct 11, 2023 | Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability ... |
| CVE-2023-38216 | MEDIUM | 5.5 | 0.4% | Oct 11, 2023 | Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that ... |
| CVE-2023-44094 | MEDIUM | 5.3 | 0.3% | Oct 11, 2023 | Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the ... |
| CVE-2023-45194 | MEDIUM | 4.3 | 0.2% | Oct 11, 2023 | Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-... |
| CVE-2023-44689 | MEDIUM | 4.3 | 0.4% | Oct 11, 2023 | e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versio... |
| CVE-2023-26220 | MEDIUM | 5.4 | 0.3% | Oct 10, 2023 | The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploita... |
| CVE-2023-36126 | MEDIUM | 6.1 | 0.4% | Oct 10, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Sc... |
| CVE-2023-45648 | MEDIUM | 5.3 | 5.8% | Oct 10, 2023 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 throug... |
| CVE-2023-45129 | MEDIUM | 4.9 | 1.2% | Oct 10, 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0... |
| CVE-2023-42795 | MEDIUM | 5.3 | 2.2% | Oct 10, 2023 | Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M... |
| CVE-2023-42794 | MEDIUM | 5.9 | 1.9% | Oct 10, 2023 | Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat ... |
| CVE-2023-41763 | MEDIUM | 5.3 | 90.4% | Oct 10, 2023 | Skype for Business Elevation of Privilege Vulnerability |
| CVE-2023-36728 | MEDIUM | 5.5 | 0.9% | Oct 10, 2023 | Microsoft SQL Server Denial of Service Vulnerability |
| CVE-2023-36724 | MEDIUM | 5.5 | 0.5% | Oct 10, 2023 | Windows Power Management Service Information Disclosure Vulnerability |
| CVE-2023-36722 | MEDIUM | 4.4 | 1.2% | Oct 10, 2023 | Active Directory Domain Services Information Disclosure Vulnerability |
| CVE-2023-36717 | MEDIUM | 6.5 | 0.7% | Oct 10, 2023 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability |
| CVE-2023-36713 | MEDIUM | 5.5 | 8.2% | Oct 10, 2023 | Windows Common Log File System Driver Information Disclosure Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now