2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6335 | HIGH | 7.8 | 0.2% | Jan 16, 2024 | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows ... |
| CVE-2023-6334 | HIGH | 7.8 | 0.1% | Jan 16, 2024 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Window... |
| CVE-2023-5097 | MEDIUM | 5.5 | 0.2% | Jan 16, 2024 | Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Wor... |
| CVE-2023-7234 | MEDIUM | 5.3 | 0.4% | Jan 16, 2024 | OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's se... |
| CVE-2023-52041 | CRITICAL | 9.8 | 0.9% | Jan 16, 2024 | An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 ... |
| CVE-2023-51381 | — | — | — | Jan 16, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by GitHub. |
| CVE-2023-49351 | CRITICAL | 9.8 | 0.6% | Jan 16, 2024 | A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows atta... |
| CVE-2023-37523 | CRITICAL | 9.8 | 0.4% | Jan 16, 2024 | Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker t... |
| CVE-2023-22525 | — | — | — | Jan 16, 2024 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2023-22520 | — | — | — | Jan 16, 2024 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2023-22514 | HIGH | 7.8 | 0.4% | Jan 16, 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and ... |
| CVE-2023-22512 | HIGH | 7.5 | 13.7% | Jan 16, 2024 | This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and S... |
| CVE-2023-22510 | — | — | — | Jan 16, 2024 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2023-22507 | — | — | — | Jan 16, 2024 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2023-22502 | — | — | — | Jan 16, 2024 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2023-4969 | MEDIUM | 6.5 | 1.2% | Jan 16, 2024 | A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU me... |
| CVE-2023-7154 | MEDIUM | 4.8 | 0.4% | Jan 16, 2024 | The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings,... |
| CVE-2023-7151 | MEDIUM | 6.1 | 0.5% | Jan 16, 2024 | The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before o... |
| CVE-2023-7125 | MEDIUM | 4.3 | 0.2% | Jan 16, 2024 | The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on t... |
| CVE-2023-7084 | MEDIUM | 5.4 | 0.4% | Jan 16, 2024 | The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authen... |
| CVE-2023-7083 | MEDIUM | 5.4 | 0.2% | Jan 16, 2024 | The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as w... |
| CVE-2023-6824 | MEDIUM | 6.5 | 0.5% | Jan 16, 2024 | The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX act... |
| CVE-2023-6741 | MEDIUM | 4.3 | 0.4% | Jan 16, 2024 | The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX act... |
| CVE-2023-6732 | MEDIUM | 4.8 | 0.4% | Jan 16, 2024 | The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which c... |
| CVE-2023-6592 | MEDIUM | 5.3 | 0.9% | Jan 16, 2024 | The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export fi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now