2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7090 | HIGH | 8.8 | 0.7% | Dec 23, 2023 | A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated... |
| CVE-2023-49594 | MEDIUM | 6.5 | 1.2% | Dec 23, 2023 | An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthentica... |
| CVE-2023-7008 | MEDIUM | 5.9 | 0.8% | Dec 23, 2023 | A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed ... |
| CVE-2023-6744 | MEDIUM | 5.4 | 0.3% | Dec 23, 2023 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all... |
| CVE-2023-5962 | MEDIUM | 6.5 | 0.3% | Dec 23, 2023 | A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prio... |
| CVE-2023-5961 | HIGH | 8.8 | 0.4% | Dec 23, 2023 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and... |
| CVE-2023-7002 | HIGH | 7.2 | 45.9% | Dec 23, 2023 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.... |
| CVE-2023-6972 | CRITICAL | 9.8 | 1.4% | Dec 23, 2023 | The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 vi... |
| CVE-2023-6971 | CRITICAL | 9.8 | 6.4% | Dec 23, 2023 | The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'con... |
| CVE-2023-51386 | LOW | 3.3 | 0.2% | Dec 22, 2023 | Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously ... |
| CVE-2023-51651 | LOW | 3.3 | 0.4% | Dec 22, 2023 | AWS SDK for PHP is the Amazon Web Services software development kit for PHP. Within the scope of requests to S3 object k... |
| CVE-2023-51650 | HIGH | 7.5 | 0.9% | Dec 22, 2023 | Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration i... |
| CVE-2023-51451 | MEDIUM | 4.3 | 0.5% | Dec 22, 2023 | Symbolicator is a service used in Sentry. Starting in Symbolicator version 0.3.3 and prior to version 21.12.1, an attack... |
| CVE-2023-51449 | HIGH | 7.5 | 2.3% | Dec 22, 2023 | Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine lear... |
| CVE-2023-51387 | HIGH | 8.8 | 1.5% | Dec 22, 2023 | Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. Th... |
| CVE-2023-50928 | CRITICAL | 9 | 0.4% | Dec 22, 2023 | "Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneousl... |
| CVE-2023-50924 | MEDIUM | 5.4 | 0.3% | Dec 22, 2023 | Englesystem is a shift planning system for chaos events. Engelsystem prior to v3.4.1 performed insufficient validation o... |
| CVE-2023-50731 | CRITICAL | 9.1 | 1.0% | Dec 22, 2023 | MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/ap... |
| CVE-2023-50730 | HIGH | 7.5 | 0.8% | Dec 22, 2023 | Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification require... |
| CVE-2023-50727 | MEDIUM | 6.1 | 0.5% | Dec 22, 2023 | Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them... |
| CVE-2023-50725 | MEDIUM | 6.1 | 0.5% | Dec 22, 2023 | Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them... |
| CVE-2023-50712 | MEDIUM | 5.4 | 0.3% | Dec 22, 2023 | Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations.... |
| CVE-2023-51035 | CRITICAL | 9.8 | 1.3% | Dec 22, 2023 | TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost ... |
| CVE-2023-51034 | CRITICAL | 9.8 | 1.1% | Dec 22, 2023 | TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareF... |
| CVE-2023-51033 | CRITICAL | 9.8 | 1.0% | Dec 22, 2023 | TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg in... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now