2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6057 | HIGH | 7.4 | 0.2% | Oct 18, 2024 | A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro... |
| CVE-2023-6056 | HIGH | 7.4 | 0.2% | Oct 18, 2024 | A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro... |
| CVE-2023-6055 | HIGH | 7.4 | 0.2% | Oct 18, 2024 | A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails ... |
| CVE-2023-6729 | HIGH | 7.3 | 0.1% | Oct 17, 2024 | Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access ... |
| CVE-2023-32196 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobject... |
| CVE-2023-32194 | HIGH | 8.6 | 0.4% | Oct 16, 2024 | A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matt... |
| CVE-2023-32193 | HIGH | 8.3 | 0.4% | Oct 16, 2024 | A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint... |
| CVE-2023-32192 | HIGH | 8.3 | 0.3% | Oct 16, 2024 | A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API ... |
| CVE-2023-32190 | HIGH | 8.5 | 0.2% | Oct 16, 2024 | mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file opera... |
| CVE-2023-22650 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from ... |
| CVE-2023-7291 | HIGH | 8.1 | 0.4% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data du... |
| CVE-2023-50780 | HIGH | 8.8 | 16.5% | Oct 14, 2024 | Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed thro... |
| CVE-2023-37154 | HIGH | 8.4 | 0.5% | Oct 9, 2024 | check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and Permi... |
| CVE-2023-6362 | HIGH | 7.3 | 0.2% | Oct 7, 2024 | A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf... |
| CVE-2023-6361 | HIGH | 7.3 | 0.2% | Oct 7, 2024 | A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf... |
| CVE-2023-37822 | HIGH | 8.2 | 0.3% | Oct 3, 2024 | The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serve... |
| CVE-2023-52946 | HIGH | 8.2 | 0.5% | Sep 26, 2024 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synolog... |
| CVE-2023-5359 | HIGH | 7.5 | 0.8% | Sep 25, 2024 | The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including... |
| CVE-2023-26691 | HIGH | 7.2 | 1.2% | Sep 25, 2024 | Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafte... |
| CVE-2023-26690 | HIGH | 8.8 | 0.7% | Sep 25, 2024 | File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/E... |
| CVE-2023-26687 | HIGH | 8.8 | 1.2% | Sep 25, 2024 | Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information ... |
| CVE-2023-47480 | HIGH | 8.4 | 0.2% | Sep 20, 2024 | An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () functi... |
| CVE-2023-30464 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack. |
| CVE-2023-41612 | HIGH | 8.8 | 0.2% | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card. |
| CVE-2023-41610 | HIGH | 8.8 | 0.4% | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now