2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50275 | HIGH | 7.5 | 1.0% | Jan 23, 2024 | HPE OneView may allow clusterService Authentication Bypass resulting in denial of service. |
| CVE-2023-50274 | HIGH | 7.8 | 0.7% | Jan 23, 2024 | HPE OneView may allow command injection with local privilege escalation. |
| CVE-2023-49657 | MEDIUM | 5.4 | 0.8% | Jan 23, 2024 | A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with... |
| CVE-2023-49783 | MEDIUM | 4.3 | 0.3% | Jan 23, 2024 | Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch p... |
| CVE-2023-48714 | MEDIUM | 4.3 | 0.4% | Jan 23, 2024 | Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to vers... |
| CVE-2023-44401 | MEDIUM | 5.3 | 0.4% | Jan 23, 2024 | The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.... |
| CVE-2023-51043 | HIGH | 7 | 0.2% | Jan 23, 2024 | In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a no... |
| CVE-2023-51042 | HIGH | 7.8 | 0.3% | Jan 23, 2024 | In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-a... |
| CVE-2023-46343 | MEDIUM | 5.5 | 0.2% | Jan 23, 2024 | In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c. |
| CVE-2023-39197 | HIGH | 7.5 | 1.0% | Jan 23, 2024 | An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This fla... |
| CVE-2023-42937 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 an... |
| CVE-2023-42935 | MEDIUM | 5.5 | 0.2% | Jan 23, 2024 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A loc... |
| CVE-2023-42915 | — | — | — | Jan 23, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-42888 | MEDIUM | 5.5 | 0.5% | Jan 23, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS V... |
| CVE-2023-42887 | MEDIUM | 6.3 | 0.2% | Jan 23, 2024 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS S... |
| CVE-2023-42881 | HIGH | 7.8 | 0.2% | Jan 23, 2024 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may l... |
| CVE-2023-40528 | MEDIUM | 5.5 | 0.2% | Jan 23, 2024 | This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, i... |
| CVE-2023-47141 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT p... |
| CVE-2023-24135 | HIGH | 7.8 | 1.3% | Jan 22, 2024 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the fu... |
| CVE-2023-7194 | MEDIUM | 6.1 | 0.3% | Jan 22, 2024 | The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the ... |
| CVE-2023-7170 | MEDIUM | 6.1 | 0.4% | Jan 22, 2024 | The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in... |
| CVE-2023-7082 | HIGH | 7.2 | 1.2% | Jan 22, 2024 | The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip... |
| CVE-2023-6626 | MEDIUM | 4.8 | 0.4% | Jan 22, 2024 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which... |
| CVE-2023-6625 | MEDIUM | 4.3 | 0.2% | Jan 22, 2024 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquir... |
| CVE-2023-6456 | MEDIUM | 4.8 | 0.3% | Jan 22, 2024 | The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow h... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now