2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48256 | MEDIUM | 6.3 | 0.3% | Jan 10, 2024 | The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies ... |
| CVE-2023-48255 | MEDIUM | 6.1 | 0.5% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary clie... |
| CVE-2023-48254 | MEDIUM | 6.1 | 0.3% | Jan 10, 2024 | The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses... |
| CVE-2023-48253 | HIGH | 8.8 | 0.9% | Jan 10, 2024 | The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication datab... |
| CVE-2023-48252 | HIGH | 8.8 | 0.6% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via craft... |
| CVE-2023-48251 | CRITICAL | 9.8 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard... |
| CVE-2023-48250 | CRITICAL | 9.8 | 0.6% | Jan 10, 2024 | The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple ... |
| CVE-2023-48249 | MEDIUM | 6.5 | 0.8% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the... |
| CVE-2023-48248 | MEDIUM | 5.4 | 0.4% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary... |
| CVE-2023-48247 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application... |
| CVE-2023-48246 | MEDIUM | 6.5 | 0.8% | Jan 10, 2024 | The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of t... |
| CVE-2023-48245 | CRITICAL | 9.8 | 0.6% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the applicati... |
| CVE-2023-48244 | MEDIUM | 6.1 | 0.3% | Jan 10, 2024 | The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses... |
| CVE-2023-48243 | HIGH | 8.8 | 1.1% | Jan 10, 2024 | The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the... |
| CVE-2023-48242 | MEDIUM | 6.5 | 0.8% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under t... |
| CVE-2023-51252 | MEDIUM | 5.4 | 0.3% | Jan 10, 2024 | PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is ... |
| CVE-2023-50120 | MEDIUM | 5.5 | 0.2% | Jan 10, 2024 | MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc... |
| CVE-2023-49619 | LOW | 3.1 | 0.9% | Jan 10, 2024 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ... |
| CVE-2023-49471 | HIGH | 8.8 | 1.1% | Jan 10, 2024 | Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validat... |
| CVE-2023-49427 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via... |
| CVE-2023-49394 | MEDIUM | 6.1 | 0.4% | Jan 10, 2024 | Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly. |
| CVE-2023-48864 | HIGH | 7.5 | 0.6% | Jan 10, 2024 | SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php. |
| CVE-2023-41603 | MEDIUM | 5.3 | 0.5% | Jan 10, 2024 | D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to... |
| CVE-2023-41781 | MEDIUM | 6.1 | 0.3% | Jan 10, 2024 | There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interfac... |
| CVE-2023-31446 | CRITICAL | 9.8 | 61.1% | Jan 10, 2024 | In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now