2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49853 | HIGH | 8.8 | 0.3% | Dec 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş. PayTR Taksit Tablosu – W... |
| CVE-2023-49844 | HIGH | 8.8 | 0.3% | Dec 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Kevin Ohashi WPPerformanceTester.This issue affects WPPerformanceTest... |
| CVE-2023-49843 | HIGH | 8.8 | 0.3% | Dec 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First... |
| CVE-2023-49840 | HIGH | 8.8 | 0.3% | Dec 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Curr... |
| CVE-2023-46177 | HIGH | 7.5 | 1.3% | Dec 18, 2023 | IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker co... |
| CVE-2023-6228 | LOW | 3.3 | 0.4% | Dec 18, 2023 | An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may ... |
| CVE-2023-5384 | LOW | 2.7 | 0.5% | Dec 18, 2023 | A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credenti... |
| CVE-2023-5236 | MEDIUM | 6.5 | 0.9% | Dec 18, 2023 | A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated at... |
| CVE-2023-5115 | MEDIUM | 6.3 | 0.9% | Dec 18, 2023 | An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a mal... |
| CVE-2023-5056 | MEDIUM | 4.1 | 0.3% | Dec 18, 2023 | A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that woul... |
| CVE-2023-4320 | HIGH | 7.5 | 0.5% | Dec 18, 2023 | An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attack... |
| CVE-2023-47038 | HIGH | 7.8 | 0.8% | Dec 18, 2023 | A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled... |
| CVE-2023-3629 | MEDIUM | 6.5 | 0.6% | Dec 18, 2023 | A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permission... |
| CVE-2023-3628 | MEDIUM | 6.5 | 0.6% | Dec 18, 2023 | A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. ... |
| CVE-2023-3430 | HIGH | 7.5 | 0.9% | Dec 18, 2023 | A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. ... |
| CVE-2023-39509 | HIGH | 7.2 | 1.5% | Dec 18, 2023 | A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative right... |
| CVE-2023-35867 | MEDIUM | 5.9 | 0.6% | Dec 18, 2023 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthe... |
| CVE-2023-32230 | HIGH | 7.5 | 0.7% | Dec 18, 2023 | An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthentica... |
| CVE-2023-28053 | MEDIUM | 5.3 | 0.4% | Dec 18, 2023 | Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SS... |
| CVE-2023-50372 | HIGH | 8.8 | 0.3% | Dec 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Post Type Page Template.This issue affects C... |
| CVE-2023-49855 | HIGH | 8.8 | 0.3% | Dec 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in BinaryCarpenter Menu Bar Cart Icon For WooCommerce By Binary Carpente... |
| CVE-2023-49854 | HIGH | 8.8 | 0.3% | Dec 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue ... |
| CVE-2023-32728 | CRITICAL | 9.8 | 0.8% | Dec 18, 2023 | The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resul... |
| CVE-2023-32727 | HIGH | 7.2 | 0.9% | Dec 18, 2023 | An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious comman... |
| CVE-2023-32726 | HIGH | 8.1 | 0.7% | Dec 18, 2023 | The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS se... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now