2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7061 | HIGH | 8.8 | 0.8% | Jul 10, 2024 | The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to,... |
| CVE-2023-21114 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati... |
| CVE-2023-21113 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati... |
| CVE-2023-50807 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A vulnerability was discovered in Samsung Wearable Processor and Modems with versions Exynos 9110, Exynos Modem 5123, Ex... |
| CVE-2023-50806 | HIGH | 8.4 | 0.2% | Jul 9, 2024 | A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Ex... |
| CVE-2023-50805 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Ex... |
| CVE-2023-50178 | HIGH | 7.4 | 0.2% | Jul 9, 2024 | An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0... |
| CVE-2023-40702 | HIGH | 7.7 | 0.4% | Jul 9, 2024 | PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentic... |
| CVE-2023-40356 | HIGH | 8.7 | 0.4% | Jul 9, 2024 | PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under cert... |
| CVE-2023-52237 | HIGH | 7.7 | 0.4% | Jul 9, 2024 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80... |
| CVE-2023-32737 | HIGH | 7 | 0.2% | Jul 9, 2024 | A vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do... |
| CVE-2023-32735 | HIGH | 7 | 0.2% | Jul 9, 2024 | A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V1... |
| CVE-2023-3288 | HIGH | 8.8 | 0.3% | Jul 9, 2024 | A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the syste... |
| CVE-2023-3287 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system... |
| CVE-2023-38055 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete t... |
| CVE-2023-38054 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete... |
| CVE-2023-38053 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete... |
| CVE-2023-38052 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a hig... |
| CVE-2023-38051 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or del... |
| CVE-2023-38050 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a... |
| CVE-2023-38049 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or ... |
| CVE-2023-38048 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete... |
| CVE-2023-38047 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delet... |
| CVE-2023-3285 | HIGH | 7.7 | 0.3% | Jul 9, 2024 | A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the sys... |
| CVE-2023-50383 | HIGH | 7.2 | 1.9% | Jul 8, 2024 | Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now