2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47105 | HIGH | 8.6 | 1.7% | Sep 18, 2024 | exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd p... |
| CVE-2023-49203 | HIGH | 7.5 | 0.6% | Sep 18, 2024 | Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb man... |
| CVE-2023-28457 | HIGH | 7.5 | 0.2% | Sep 18, 2024 | An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and i... |
| CVE-2023-28456 | HIGH | 7.5 | 0.5% | Sep 18, 2024 | An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more... |
| CVE-2023-28455 | HIGH | 7.5 | 0.5% | Sep 18, 2024 | An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using... |
| CVE-2023-28452 | HIGH | 7.5 | 0.6% | Sep 18, 2024 | An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a ... |
| CVE-2023-28451 | HIGH | 7.5 | 0.5% | Sep 18, 2024 | An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which ... |
| CVE-2023-45854 | HIGH | 7.5 | 0.3% | Sep 16, 2024 | A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shoppin... |
| CVE-2023-43626 | HIGH | 8.7 | 0.1% | Sep 16, 2024 | Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable ... |
| CVE-2023-42772 | HIGH | 8.7 | 0.2% | Sep 16, 2024 | Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to pot... |
| CVE-2023-41833 | HIGH | 8.7 | 0.1% | Sep 16, 2024 | A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalat... |
| CVE-2023-6841 | HIGH | 7.5 | 0.7% | Sep 10, 2024 | A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an atta... |
| CVE-2023-37233 | HIGH | 8.8 | 0.4% | Sep 10, 2024 | Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks. |
| CVE-2023-37232 | HIGH | 7.5 | 0.4% | Sep 10, 2024 | Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor. |
| CVE-2023-37230 | HIGH | 8.8 | 0.3% | Sep 10, 2024 | Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF. |
| CVE-2023-37229 | HIGH | 8.8 | 0.3% | Sep 10, 2024 | Loftware Spectrum before 5.1 allows SSRF. |
| CVE-2023-30756 | HIGH | 8.2 | 0.5% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP... |
| CVE-2023-28827 | HIGH | 8.2 | 0.5% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP... |
| CVE-2023-46809 | HIGH | 7.4 | 1.3% | Sep 7, 2024 | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL whi... |
| CVE-2023-30587 | HIGH | 7.5 | 0.7% | Sep 7, 2024 | A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using ... |
| CVE-2023-30584 | HIGH | 7.7 | 0.4% | Sep 7, 2024 | A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f... |
| CVE-2023-30583 | HIGH | 7.5 | 0.7% | Sep 7, 2024 | fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--all... |
| CVE-2023-51367 | HIGH | 8.8 | 0.4% | Sep 6, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2023-50360 | HIGH | 8.8 | 0.4% | Sep 6, 2024 | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow aut... |
| CVE-2023-47563 | HIGH | 8.8 | 1.0% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now