2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51837 | CRITICAL | 9.8 | 0.5% | Jan 30, 2024 | Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation. |
| CVE-2023-51813 | MEDIUM | 6.5 | 0.4% | Jan 30, 2024 | Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote at... |
| CVE-2023-37571 | MEDIUM | 6.1 | 0.3% | Jan 30, 2024 | Softing TH SCOPE through 3.70 allows XSS. |
| CVE-2023-4554 | MEDIUM | 6.5 | 0.4% | Jan 29, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Serv... |
| CVE-2023-4553 | MEDIUM | 5.3 | 0.4% | Jan 29, 2024 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder... |
| CVE-2023-4552 | HIGH | 7.1 | 0.4% | Jan 29, 2024 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenti... |
| CVE-2023-4551 | HIGH | 8.8 | 1.0% | Jan 29, 2024 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBu... |
| CVE-2023-4550 | HIGH | 7.5 | 0.5% | Jan 29, 2024 | Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on W... |
| CVE-2023-49038 | HIGH | 7.2 | 1.8% | Jan 29, 2024 | Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbit... |
| CVE-2023-51842 | HIGH | 7.5 | 0.8% | Jan 29, 2024 | An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16. |
| CVE-2023-51840 | CRITICAL | 9.8 | 0.6% | Jan 29, 2024 | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key. |
| CVE-2023-51839 | CRITICAL | 9.1 | 0.4% | Jan 29, 2024 | DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm. |
| CVE-2023-30970 | MEDIUM | 6.5 | 0.5% | Jan 29, 2024 | Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated use... |
| CVE-2023-22836 | MEDIUM | 5.4 | 0.3% | Jan 29, 2024 | In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from t... |
| CVE-2023-40551 | MEDIUM | 5.1 | 0.4% | Jan 29, 2024 | A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposu... |
| CVE-2023-40550 | MEDIUM | 5.5 | 0.4% | Jan 29, 2024 | An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensi... |
| CVE-2023-40549 | MEDIUM | 5.5 | 0.4% | Jan 29, 2024 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE bin... |
| CVE-2023-40546 | MEDIUM | 5.5 | 0.4% | Jan 29, 2024 | A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new varia... |
| CVE-2023-1705 | HIGH | 7.8 | 0.1% | Jan 29, 2024 | Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) all... |
| CVE-2023-7204 | HIGH | 7.5 | 0.6% | Jan 29, 2024 | The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provid... |
| CVE-2023-7200 | MEDIUM | 6.1 | 0.4% | Jan 29, 2024 | The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page... |
| CVE-2023-7199 | MEDIUM | 5.3 | 0.6% | Jan 29, 2024 | The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthentica... |
| CVE-2023-7089 | MEDIUM | 5.4 | 0.4% | Jan 29, 2024 | The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a rol... |
| CVE-2023-7074 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2023-6946 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which cou... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now