2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48401 | MEDIUM | 5.5 | 0.1% | Dec 8, 2023 | In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check.... |
| CVE-2023-48399 | MEDIUM | 5.5 | 0.1% | Dec 8, 2023 | In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a miss... |
| CVE-2023-48398 | HIGH | 7.5 | 0.3% | Dec 8, 2023 | In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds rea... |
| CVE-2023-48397 | MEDIUM | 4.9 | 0.4% | Dec 8, 2023 | In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lea... |
| CVE-2023-47565 | HIGH | 8.8 | 73.3% | Dec 8, 2023 | An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. ... |
| CVE-2023-32975 | HIGH | 7.2 | 0.9% | Dec 8, 2023 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2023-32968 | HIGH | 7.2 | 0.8% | Dec 8, 2023 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2023-23372 | MEDIUM | 6.1 | 0.5% | Dec 8, 2023 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2023-6611 | HIGH | 7.5 | 0.6% | Dec 8, 2023 | A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unk... |
| CVE-2023-6609 | MEDIUM | 6.1 | 0.4% | Dec 8, 2023 | A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the fi... |
| CVE-2023-6608 | HIGH | 7.5 | 0.6% | Dec 8, 2023 | A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknow... |
| CVE-2023-6245 | HIGH | 7.5 | 1.2% | Dec 8, 2023 | The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For exa... |
| CVE-2023-6146 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in th... |
| CVE-2023-49487 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management depar... |
| CVE-2023-49486 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department... |
| CVE-2023-49485 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management departmen... |
| CVE-2023-49484 | MEDIUM | 5.4 | 0.4% | Dec 8, 2023 | Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management depart... |
| CVE-2023-49444 | MEDIUM | 5.4 | 0.5% | Dec 8, 2023 | An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a craft... |
| CVE-2023-49443 | CRITICAL | 9.8 | 0.8% | Dec 8, 2023 | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerabil... |
| CVE-2023-6607 | HIGH | 7.5 | 0.7% | Dec 8, 2023 | A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability ... |
| CVE-2023-49007 | CRITICAL | 9.8 | 9.0% | Dec 8, 2023 | In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd. |
| CVE-2023-46157 | HIGH | 8.8 | 2.3% | Dec 8, 2023 | File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by c... |
| CVE-2023-45866 | MEDIUM | 6.3 | 7.9% | Dec 8, 2023 | Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encry... |
| CVE-2023-32460 | HIGH | 7.8 | 0.2% | Dec 8, 2023 | Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker... |
| CVE-2023-48929 | CRITICAL | 9.8 | 0.8% | Dec 8, 2023 | Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' p... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now