2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49952 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header. |
| CVE-2023-39180 | HIGH | 7.5 | 1.4% | Nov 18, 2024 | A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releas... |
| CVE-2023-39179 | HIGH | 7.5 | 1.1% | Nov 18, 2024 | A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack o... |
| CVE-2023-39176 | HIGH | 7.5 | 0.7% | Nov 18, 2024 | A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue ... |
| CVE-2023-4639 | HIGH | 7.4 | 1.1% | Nov 17, 2024 | A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requ... |
| CVE-2023-20154 | HIGH | 8.1 | 0.9% | Nov 15, 2024 | A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote a... |
| CVE-2023-20125 | HIGH | 8.6 | 0.9% | Nov 15, 2024 | A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacke... |
| CVE-2023-4458 | HIGH | 7.5 | 0.8% | Nov 14, 2024 | A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack o... |
| CVE-2023-35686 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This... |
| CVE-2023-35659 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the... |
| CVE-2023-50176 | HIGH | 8.8 | 0.6% | Nov 12, 2024 | A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allo... |
| CVE-2023-47543 | HIGH | 8.1 | 0.4% | Nov 12, 2024 | An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 throug... |
| CVE-2023-32736 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMAT... |
| CVE-2023-1973 | HIGH | 7.5 | 1.3% | Nov 7, 2024 | A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of ... |
| CVE-2023-29126 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force pro... |
| CVE-2023-29125 | HIGH | 8 | 0.3% | Nov 5, 2024 | A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700. |
| CVE-2023-29121 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system. |
| CVE-2023-29120 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s priv... |
| CVE-2023-29119 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.ph... |
| CVE-2023-29118 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.p... |
| CVE-2023-29117 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox... |
| CVE-2023-52066 | HIGH | 7.2 | 0.3% | Oct 30, 2024 | http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter. |
| CVE-2023-50310 | HIGH | 7.5 | 0.4% | Oct 23, 2024 | IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses ... |
| CVE-2023-6080 | HIGH | 7.8 | 0.2% | Oct 18, 2024 | Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnera... |
| CVE-2023-49570 | HIGH | 7.4 | 0.2% | Oct 18, 2024 | A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now