2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38538 | MEDIUM | 5 | 0.2% | Oct 4, 2023 | A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could ha... |
| CVE-2023-38537 | MEDIUM | 5.6 | 0.2% | Oct 4, 2023 | A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incomi... |
| CVE-2023-3576 | MEDIUM | 5.5 | 0.3% | Oct 4, 2023 | A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image fil... |
| CVE-2023-3428 | MEDIUM | 5.5 | 0.3% | Oct 4, 2023 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local atta... |
| CVE-2023-27121 | MEDIUM | 6.1 | 21.3% | Oct 4, 2023 | A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasa... |
| CVE-2023-5371 | MEDIUM | 6.5 | 0.5% | Oct 4, 2023 | RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection... |
| CVE-2023-5113 | MEDIUM | 6.1 | 0.3% | Oct 4, 2023 | Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to W... |
| CVE-2023-4380 | MEDIUM | 6.3 | 0.5% | Oct 4, 2023 | A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, th... |
| CVE-2023-3971 | MEDIUM | 5.4 | 0.7% | Oct 4, 2023 | An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture c... |
| CVE-2023-40684 | MEDIUM | 5.4 | 0.3% | Oct 4, 2023 | IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. T... |
| CVE-2023-40376 | MEDIUM | 6.5 | 0.5% | Oct 4, 2023 | IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations cou... |
| CVE-2023-4497 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr... |
| CVE-2023-4496 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr... |
| CVE-2023-4495 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr... |
| CVE-2023-4493 | MEDIUM | 5.4 | 0.4% | Oct 4, 2023 | Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects m... |
| CVE-2023-4492 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, mid... |
| CVE-2023-4090 | MEDIUM | 6.1 | 0.3% | Oct 4, 2023 | Cross-site Scripting (XSS) reflected vulnerability on WideStand until 5.3.5 version, which generates one of the meta tag... |
| CVE-2023-4037 | MEDIUM | 5.5 | 0.3% | Oct 4, 2023 | Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local a... |
| CVE-2023-3153 | MEDIUM | 5.3 | 1.0% | Oct 4, 2023 | A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could al... |
| CVE-2023-5375 | MEDIUM | 6.1 | 33.6% | Oct 4, 2023 | Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2. |
| CVE-2023-44272 | MEDIUM | 5.4 | 0.4% | Oct 4, 2023 | A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant mes... |
| CVE-2023-5370 | MEDIUM | 5.5 | 0.2% | Oct 4, 2023 | On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no spe... |
| CVE-2023-5368 | MEDIUM | 6.5 | 0.5% | Oct 4, 2023 | On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional... |
| CVE-2023-30737 | MEDIUM | 5.5 | 0.2% | Oct 4, 2023 | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive... |
| CVE-2023-30736 | MEDIUM | 5.4 | 0.2% | Oct 4, 2023 | Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute java... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now