2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38513 | MEDIUM | 5.4 | 0.3% | Dec 20, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).... |
| CVE-2023-37871 | HIGH | 7.5 | 0.5% | Dec 20, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: ... |
| CVE-2023-6562 | HIGH | 7.5 | 0.7% | Dec 20, 2023 | JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachab... |
| CVE-2023-6912 | CRITICAL | 9.8 | 1.0% | Dec 20, 2023 | Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authe... |
| CVE-2023-6910 | MEDIUM | 6.5 | 0.9% | Dec 20, 2023 | A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticat... |
| CVE-2023-6769 | MEDIUM | 4.6 | 0.7% | Dec 20, 2023 | Stored XSS vulnerability in Amazing Little Poll, affecting versions 1.3 and 1.4. This vulnerability allows a remote atta... |
| CVE-2023-6768 | CRITICAL | 9.8 | 1.0% | Dec 20, 2023 | Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allo... |
| CVE-2023-50628 | CRITICAL | 9.8 | 1.2% | Dec 20, 2023 | Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive ... |
| CVE-2023-50044 | CRITICAL | 9.8 | 0.9% | Dec 20, 2023 | Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an i... |
| CVE-2023-37544 | HIGH | 7.5 | 1.4% | Dec 20, 2023 | Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong en... |
| CVE-2023-0011 | MEDIUM | 6.8 | 0.5% | Dec 20, 2023 | A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specificall... |
| CVE-2023-6977 | HIGH | 7.5 | 3.9% | Dec 20, 2023 | This vulnerability enables malicious users to read sensitive files on the server. |
| CVE-2023-6976 | HIGH | 8.8 | 1.0% | Dec 20, 2023 | This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the contex... |
| CVE-2023-6975 | CRITICAL | 9.8 | 2.0% | Dec 20, 2023 | A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models... |
| CVE-2023-6974 | CRITICAL | 9.8 | 1.5% | Dec 20, 2023 | A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it cou... |
| CVE-2023-47707 | MEDIUM | 5.4 | 0.4% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2023-47705 | MEDIUM | 4.3 | 0.5% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to imp... |
| CVE-2023-47703 | MEDIUM | 5.3 | 0.8% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a det... |
| CVE-2023-47702 | CRITICAL | 9.1 | 1.0% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An ... |
| CVE-2023-47706 | HIGH | 8.8 | 0.8% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file ty... |
| CVE-2023-47704 | HIGH | 7.5 | 0.6% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source co... |
| CVE-2023-27172 | CRITICAL | 9.1 | 0.7% | Dec 20, 2023 | Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the ... |
| CVE-2023-6689 | HIGH | 8.8 | 0.3% | Dec 20, 2023 | A successful CSRF attack could force the user to perform state changing requests on the application. If the victim ... |
| CVE-2023-50707 | HIGH | 7.5 | 0.7% | Dec 20, 2023 | Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service c... |
| CVE-2023-50706 | MEDIUM | 4.3 | 0.2% | Dec 20, 2023 | A user without administrator permissions with access to the UC500 windows system could perform a memory dum... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now