2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41744 | HIGH | 7.8 | 0.1% | Aug 31, 2023 | Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron... |
| CVE-2023-41743 | HIGH | 7.8 | 0.3% | Aug 31, 2023 | Local privilege escalation due to insecure driver communication port permissions. The following products are affected: A... |
| CVE-2023-34392 | HIGH | 8.8 | 0.5% | Aug 31, 2023 | A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Gr... |
| CVE-2023-31173 | HIGH | 8.4 | 0.2% | Aug 31, 2023 | Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Win... |
| CVE-2023-31172 | HIGH | 7.4 | 0.3% | Aug 31, 2023 | An Incomplete Filtering of Special Elements vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerat... |
| CVE-2023-31167 | HIGH | 8.1 | 0.4% | Aug 31, 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering L... |
| CVE-2023-41742 | HIGH | 7.5 | 0.4% | Aug 31, 2023 | Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agen... |
| CVE-2023-41640 | HIGH | 8.8 | 0.9% | Aug 31, 2023 | An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows ... |
| CVE-2023-41638 | HIGH | 8.8 | 1.0% | Aug 31, 2023 | An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attack... |
| CVE-2023-33835 | HIGH | 7.5 | 0.6% | Aug 31, 2023 | IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th... |
| CVE-2023-41741 | HIGH | 7.5 | 0.7% | Aug 31, 2023 | Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SR... |
| CVE-2023-41738 | HIGH | 8.8 | 1.5% | Aug 31, 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Do... |
| CVE-2023-20900 | HIGH | 7.5 | 1.2% | Aug 31, 2023 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vspher... |
| CVE-2023-3677 | HIGH | 8.8 | 0.6% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in vers... |
| CVE-2023-3636 | HIGH | 8.8 | 0.7% | Aug 31, 2023 | The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.... |
| CVE-2023-2229 | HIGH | 8.8 | 0.7% | Aug 31, 2023 | The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, an... |
| CVE-2023-3489 | HIGH | 7.5 | 0.3% | Aug 31, 2023 | The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in t... |
| CVE-2023-39139 | HIGH | 7.8 | 0.3% | Aug 30, 2023 | An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file. |
| CVE-2023-39138 | HIGH | 7.8 | 0.4% | Aug 30, 2023 | An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file. |
| CVE-2023-39137 | HIGH | 7.8 | 0.3% | Aug 30, 2023 | An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing. |
| CVE-2023-39135 | HIGH | 7.8 | 0.4% | Aug 30, 2023 | An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry. |
| CVE-2023-41039 | HIGH | 7.7 | 0.6% | Aug 30, 2023 | RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality... |
| CVE-2023-4640 | HIGH | 7.5 | 0.3% | Aug 30, 2023 | The controller responsible for setting the logging level does not include any authorization checks to ensure the user is... |
| CVE-2023-4571 | HIGH | 8.6 | 0.2% | Aug 30, 2023 | In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject Am... |
| CVE-2023-40598 | HIGH | 8.8 | 0.6% | Aug 30, 2023 | In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a leg... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now