2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43481 | CRITICAL | 9.8 | 1.1% | Dec 27, 2023 | An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att... |
| CVE-2023-52075 | HIGH | 7.5 | 0.5% | Dec 27, 2023 | ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f8... |
| CVE-2023-40038 | HIGH | 8.8 | 0.3% | Dec 27, 2023 | Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They... |
| CVE-2023-52077 | CRITICAL | 9.8 | 0.7% | Dec 27, 2023 | Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allow... |
| CVE-2023-51700 | CRITICAL | 9.8 | 0.5% | Dec 27, 2023 | Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your Wo... |
| CVE-2023-51697 | HIGH | 7.5 | 0.3% | Dec 27, 2023 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti... |
| CVE-2023-51665 | HIGH | 7.5 | 0.3% | Dec 27, 2023 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti... |
| CVE-2023-51664 | CRITICAL | 9.8 | 3.4% | Dec 27, 2023 | tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/chan... |
| CVE-2023-51443 | MEDIUM | 5.9 | 1.5% | Dec 27, 2023 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2023-50255 | HIGH | 7.8 | 1.1% | Dec 27, 2023 | Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerab... |
| CVE-2023-7116 | CRITICAL | 9.8 | 9.9% | Dec 27, 2023 | A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue ... |
| CVE-2023-4641 | MEDIUM | 5.5 | 0.3% | Dec 27, 2023 | A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password ... |
| CVE-2023-3171 | HIGH | 7.5 | 0.9% | Dec 27, 2023 | A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTabl... |
| CVE-2023-6190 | CRITICAL | 9.8 | 0.8% | Dec 27, 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi Unive... |
| CVE-2023-52096 | HIGH | 7.5 | 0.6% | Dec 26, 2023 | SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (su... |
| CVE-2023-49438 | MEDIUM | 6.1 | 1.1% | Dec 26, 2023 | An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspectin... |
| CVE-2023-48003 | MEDIUM | 6.1 | 0.5% | Dec 26, 2023 | An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redire... |
| CVE-2023-6268 | MEDIUM | 6.1 | 0.4% | Dec 26, 2023 | The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting... |
| CVE-2023-6250 | HIGH | 7.5 | 0.5% | Dec 26, 2023 | The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthe... |
| CVE-2023-6166 | MEDIUM | 6.1 | 0.4% | Dec 26, 2023 | The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, lead... |
| CVE-2023-6155 | MEDIUM | 5.3 | 0.6% | Dec 26, 2023 | The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX acti... |
| CVE-2023-6114 | HIGH | 7.5 | 30.9% | Dec 26, 2023 | The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listin... |
| CVE-2023-5991 | CRITICAL | 9.8 | 3.3% | Dec 26, 2023 | The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as do... |
| CVE-2023-5980 | MEDIUM | 4.8 | 0.4% | Dec 26, 2023 | The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow... |
| CVE-2023-5939 | HIGH | 7.2 | 1.3% | Dec 26, 2023 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now