2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2460 | HIGH | 7.1 | 0.7% | May 3, 2023 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who... |
| CVE-2023-31435 | HIGH | 8.1 | 0.7% | May 2, 2023 | Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire p... |
| CVE-2023-31433 | HIGH | 8.8 | 0.9% | May 2, 2023 | A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated atta... |
| CVE-2023-30944 | HIGH | 7.3 | 1.1% | May 2, 2023 | The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki ... |
| CVE-2023-30403 | HIGH | 7.5 | 14.9% | May 2, 2023 | An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows ... |
| CVE-2023-26546 | HIGH | 8.8 | 1.4% | May 2, 2023 | European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Si... |
| CVE-2023-30861 | HIGH | 7.5 | 1.3% | May 2, 2023 | Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containi... |
| CVE-2023-32007 | HIGH | 8.8 | 75.8% | May 2, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option s... |
| CVE-2023-1196 | HIGH | 8.8 | 1.1% | May 2, 2023 | The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user ... |
| CVE-2023-1809 | HIGH | 7.5 | 0.7% | May 2, 2023 | The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowin... |
| CVE-2023-1669 | HIGH | 7.2 | 18.5% | May 2, 2023 | The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-p... |
| CVE-2023-0924 | HIGH | 7.2 | 1.0% | May 2, 2023 | The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowin... |
| CVE-2023-21666 | HIGH | 7.8 | 0.2% | May 2, 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | HIGH | 7.8 | 0.2% | May 2, 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2023-21642 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption in HAB Memory management due to broad system privileges via physical address. |
| CVE-2023-27035 | HIGH | 7.5 | 1.8% | May 1, 2023 | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio an... |
| CVE-2023-22922 | HIGH | 7.5 | 0.9% | May 1, 2023 | A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot... |
| CVE-2023-22921 | HIGH | 7.5 | 0.5% | May 1, 2023 | A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could al... |
| CVE-2023-22919 | HIGH | 8.8 | 1.6% | May 1, 2023 | The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allo... |
| CVE-2023-25492 | HIGH | 8.8 | 0.5% | May 1, 2023 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined ... |
| CVE-2023-0683 | HIGH | 8.8 | 0.6% | May 1, 2023 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API ca... |
| CVE-2023-30063 | HIGH | 7.5 | 1.1% | May 1, 2023 | D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass. |
| CVE-2023-30061 | HIGH | 7.5 | 1.1% | May 1, 2023 | D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi. |
| CVE-2023-0896 | HIGH | 8.8 | 0.4% | May 1, 2023 | A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device... |
| CVE-2023-2236 | HIGH | 7.8 | 0.4% | May 1, 2023 | A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escala... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now