2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4140 | HIGH | 8.8 | 0.6% | Aug 4, 2023 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including... |
| CVE-2023-4139 | HIGH | 7.5 | 0.6% | Aug 4, 2023 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing... |
| CVE-2023-38708 | HIGH | 8.8 | 0.5% | Aug 4, 2023 | Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path ... |
| CVE-2023-30146 | HIGH | 7.5 | 0.6% | Aug 4, 2023 | Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy o... |
| CVE-2023-36135 | HIGH | 7.5 | 0.5% | Aug 4, 2023 | User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, whe... |
| CVE-2023-30297 | HIGH | 7 | 0.2% | Aug 4, 2023 | An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code v... |
| CVE-2023-0525 | HIGH | 7.5 | 0.5% | Aug 4, 2023 | Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000... |
| CVE-2023-38952 | HIGH | 7.5 | 2.4% | Aug 3, 2023 | Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due ... |
| CVE-2023-38950 | HIGH | 7.5 | 84.9% | Aug 3, 2023 | A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbit... |
| CVE-2023-38949 | HIGH | 7.5 | 0.4% | Aug 3, 2023 | An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrato... |
| CVE-2023-37498 | HIGH | 8.8 | 0.5% | Aug 3, 2023 | A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It... |
| CVE-2023-37497 | HIGH | 8.8 | 0.4% | Aug 3, 2023 | The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated ... |
| CVE-2023-20216 | HIGH | 7.8 | 0.1% | Aug 3, 2023 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authentica... |
| CVE-2023-39121 | HIGH | 7.2 | 2.3% | Aug 3, 2023 | emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php. |
| CVE-2023-0956 | HIGH | 7.5 | 0.8% | Aug 3, 2023 | External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without ... |
| CVE-2023-35081 | HIGH | 7.2 | 63.3% | Aug 3, 2023 | A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) a... |
| CVE-2023-32764 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator. |
| CVE-2023-38948 | HIGH | 7.2 | 0.9% | Aug 3, 2023 | An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers t... |
| CVE-2023-38947 | HIGH | 7.2 | 0.5% | Aug 3, 2023 | An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to ex... |
| CVE-2023-33366 | HIGH | 8.8 | 0.6% | Aug 3, 2023 | A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbit... |
| CVE-2023-33365 | HIGH | 7.5 | 0.7% | Aug 3, 2023 | A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch... |
| CVE-2023-33364 | HIGH | 8.8 | 1.5% | Aug 3, 2023 | An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to exe... |
| CVE-2023-33363 | HIGH | 7.5 | 0.6% | Aug 3, 2023 | An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to a... |
| CVE-2023-36299 | HIGH | 8.8 | 1.4% | Aug 3, 2023 | A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and opt... |
| CVE-2023-36298 | HIGH | 8.8 | 1.2% | Aug 3, 2023 | DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE). |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now