2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48378 | HIGH | 7.5 | 1.3% | Dec 15, 2023 | Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated r... |
| CVE-2023-48376 | CRITICAL | 9.8 | 1.0% | Dec 15, 2023 | SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file... |
| CVE-2023-48375 | HIGH | 8.8 | 0.7% | Dec 15, 2023 | SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users ar... |
| CVE-2023-48374 | MEDIUM | 6.5 | 0.6% | Dec 15, 2023 | SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific a... |
| CVE-2023-48373 | HIGH | 7.5 | 1.3% | Dec 15, 2023 | ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauth... |
| CVE-2023-48372 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attack... |
| CVE-2023-48371 | CRITICAL | 9.8 | 1.0% | Dec 15, 2023 | ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated r... |
| CVE-2023-50715 | MEDIUM | 4.3 | 0.9% | Dec 15, 2023 | Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active ... |
| CVE-2023-6832 | MEDIUM | 4.3 | 0.5% | Dec 15, 2023 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-6831 | HIGH | 8.1 | 3.3% | Dec 15, 2023 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2. |
| CVE-2023-48050 | CRITICAL | 9.8 | 0.8% | Dec 15, 2023 | SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka ... |
| CVE-2023-42183 | MEDIUM | 5.3 | 0.6% | Dec 15, 2023 | lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of i... |
| CVE-2023-40954 | CRITICAL | 9.8 | 0.9% | Dec 15, 2023 | A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12... |
| CVE-2023-36878 | MEDIUM | 4.3 | 0.9% | Dec 15, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2023-48049 | CRITICAL | 9.8 | 1.0% | Dec 15, 2023 | A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through... |
| CVE-2023-4489 | CRITICAL | 9.8 | 0.5% | Dec 14, 2023 | The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP G... |
| CVE-2023-6707 | HIGH | 8.8 | 0.6% | Dec 14, 2023 | Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2023-6706 | HIGH | 8.8 | 0.6% | Dec 14, 2023 | Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engag... |
| CVE-2023-6705 | HIGH | 8.8 | 0.7% | Dec 14, 2023 | Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap ... |
| CVE-2023-6704 | HIGH | 8.8 | 0.7% | Dec 14, 2023 | Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap... |
| CVE-2023-6703 | HIGH | 8.8 | 0.6% | Dec 14, 2023 | Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-6702 | HIGH | 8.8 | 43.2% | Dec 14, 2023 | Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2023-6134 | MEDIUM | 5.4 | 0.9% | Dec 14, 2023 | A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to t... |
| CVE-2023-49347 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or ma... |
| CVE-2023-49346 | HIGH | 7.8 | 0.3% | Dec 14, 2023 | Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now