2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39912 | MEDIUM | 4.9 | 4.0% | Aug 31, 2023 | Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine wh... |
| CVE-2023-4688 | MEDIUM | 5.5 | 0.2% | Aug 31, 2023 | Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows)... |
| CVE-2023-41751 | MEDIUM | 5.5 | 0.1% | Aug 31, 2023 | Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acron... |
| CVE-2023-41750 | MEDIUM | 5.5 | 0.2% | Aug 31, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux... |
| CVE-2023-41747 | MEDIUM | 6.5 | 0.4% | Aug 31, 2023 | Sensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Clo... |
| CVE-2023-41745 | MEDIUM | 5.5 | 0.2% | Aug 31, 2023 | Sensitive information disclosure due to excessive collection of system information. The following products are affected:... |
| CVE-2023-41045 | MEDIUM | 5.3 | 0.3% | Aug 31, 2023 | Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Gr... |
| CVE-2023-4683 | MEDIUM | 5.5 | 0.3% | Aug 31, 2023 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV. |
| CVE-2023-4682 | MEDIUM | 5.5 | 0.3% | Aug 31, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. |
| CVE-2023-4681 | MEDIUM | 5.5 | 0.3% | Aug 31, 2023 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV. |
| CVE-2023-4678 | MEDIUM | 5.5 | 0.3% | Aug 31, 2023 | Divide By Zero in GitHub repository gpac/gpac prior to 2.3-DEV. |
| CVE-2023-41717 | MEDIUM | 5.5 | 0.4% | Aug 31, 2023 | Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file downl... |
| CVE-2023-34391 | MEDIUM | 5.5 | 0.1% | Aug 31, 2023 | Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software o... |
| CVE-2023-31174 | MEDIUM | 6.5 | 0.2% | Aug 31, 2023 | A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configur... |
| CVE-2023-31171 | MEDIUM | 6.5 | 0.3% | Aug 31, 2023 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Schweitzer... |
| CVE-2023-31170 | MEDIUM | 6.5 | 0.3% | Aug 31, 2023 | An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE... |
| CVE-2023-31169 | MEDIUM | 5.7 | 0.4% | Aug 31, 2023 | An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator ... |
| CVE-2023-31168 | MEDIUM | 6.5 | 0.4% | Aug 31, 2023 | An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE... |
| CVE-2023-41642 | MEDIUM | 6.1 | 1.1% | Aug 31, 2023 | Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealG... |
| CVE-2023-41635 | MEDIUM | 6.5 | 0.7% | Aug 31, 2023 | A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 al... |
| CVE-2023-33834 | MEDIUM | 5.3 | 0.5% | Aug 31, 2023 | IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th... |
| CVE-2023-41740 | MEDIUM | 5.3 | 0.8% | Aug 31, 2023 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synolog... |
| CVE-2023-41739 | MEDIUM | 6.5 | 0.7% | Aug 31, 2023 | Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346... |
| CVE-2023-4500 | MEDIUM | 4.8 | 0.3% | Aug 31, 2023 | The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter ... |
| CVE-2023-4471 | MEDIUM | 6.1 | 0.5% | Aug 31, 2023 | The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_d... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now