2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31813 | — | — | — | Dec 16, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-2804. Reason: This record is a duplicate of CVE-2023-2... |
| CVE-2023-28022 | MEDIUM | 6.5 | 0.5% | Dec 15, 2023 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in... |
| CVE-2023-27317 | MEDIUM | 4.6 | 0.4% | Dec 15, 2023 | ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached ... |
| CVE-2023-50728 | HIGH | 7.5 | 0.7% | Dec 15, 2023 | octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2,... |
| CVE-2023-50469 | CRITICAL | 9.8 | 8.9% | Dec 15, 2023 | Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEnc... |
| CVE-2023-50266 | MEDIUM | 5.3 | 0.6% | Dec 15, 2023 | Bazarr manages and downloads subtitles. In version 1.2.4, the proxy method in bazarr/bazarr/app/ui.py does not validate ... |
| CVE-2023-50265 | HIGH | 7.5 | 0.9% | Dec 15, 2023 | Bazarr manages and downloads subtitles. Prior to 1.3.1, the /api/swaggerui/static endpoint in bazarr/app/ui.py does not ... |
| CVE-2023-50264 | HIGH | 7.5 | 0.9% | Dec 15, 2023 | Bazarr manages and downloads subtitles. Prior to 1.3.1, Bazarr contains an arbitrary file read in /system/backup/downloa... |
| CVE-2023-4020 | CRITICAL | 9.1 | 0.6% | Dec 15, 2023 | An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon... |
| CVE-2023-50723 | HIGH | 8.8 | 1.2% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone... |
| CVE-2023-50722 | HIGH | 8.8 | 0.7% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there ... |
| CVE-2023-50721 | HIGH | 8.8 | 78.8% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, t... |
| CVE-2023-50720 | MEDIUM | 5.3 | 59.1% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in X... |
| CVE-2023-50719 | HIGH | 7.5 | 83.5% | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-... |
| CVE-2023-50918 | CRITICAL | 9.8 | 0.8% | Dec 15, 2023 | app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs. |
| CVE-2023-50917 | CRITICAL | 9.8 | 38.3% | Dec 15, 2023 | MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: ... |
| CVE-2023-50089 | CRITICAL | 9.8 | 4.0% | Dec 15, 2023 | A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication,... |
| CVE-2023-6680 | HIGH | 8.1 | 0.4% | Dec 15, 2023 | An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior... |
| CVE-2023-6051 | MEDIUM | 6.5 | 0.6% | Dec 15, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 befor... |
| CVE-2023-5512 | MEDIUM | 5.7 | 0.5% | Dec 15, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from ... |
| CVE-2023-5310 | MEDIUM | 6.5 | 0.3% | Dec 15, 2023 | A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v... |
| CVE-2023-5061 | MEDIUM | 4.3 | 0.4% | Dec 15, 2023 | An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting fro... |
| CVE-2023-49829 | MEDIUM | 4.8 | 0.4% | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS ... |
| CVE-2023-49823 | MEDIUM | 5.4 | 0.5% | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Pa... |
| CVE-2023-49767 | MEDIUM | 4.8 | 0.4% | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship:... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now