2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29815 | HIGH | 8.8 | 0.3% | Apr 28, 2023 | mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2023-1477 | HIGH | 8.8 | 0.6% | Apr 28, 2023 | Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue af... |
| CVE-2023-2373 | HIGH | 7.2 | 4.3% | Apr 28, 2023 | A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of... |
| CVE-2023-2360 | HIGH | 7.5 | 0.4% | Apr 28, 2023 | Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infras... |
| CVE-2023-28882 | HIGH | 7.5 | 0.7% | Apr 28, 2023 | Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) be... |
| CVE-2023-28528 | HIGH | 7.8 | 1.5% | Apr 28, 2023 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c... |
| CVE-2023-31436 | HIGH | 7.8 | 0.6% | Apr 28, 2023 | qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can... |
| CVE-2023-27557 | HIGH | 7.5 | 0.4% | Apr 28, 2023 | IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6... |
| CVE-2023-27556 | HIGH | 7.5 | 1.0% | Apr 28, 2023 | IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02... |
| CVE-2023-2356 | HIGH | 7.5 | 4.2% | Apr 28, 2023 | Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1. |
| CVE-2023-29169 | HIGH | 8.8 | 0.7% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-29150 | HIGH | 8.8 | 0.7% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-28716 | HIGH | 8.8 | 4.5% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-28400 | HIGH | 8.8 | 24.6% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-28384 | HIGH | 8.8 | 44.8% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-30380 | HIGH | 7.5 | 1.2% | Apr 27, 2023 | An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal... |
| CVE-2023-25437 | HIGH | 8.8 | 14.1% | Apr 27, 2023 | An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges an... |
| CVE-2023-2355 | HIGH | 7.8 | 0.2% | Apr 27, 2023 | Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deplo... |
| CVE-2023-21712 | HIGH | 8.1 | 1.0% | Apr 27, 2023 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-2335 | HIGH | 7.5 | 0.3% | Apr 27, 2023 | Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Regi... |
| CVE-2023-30850 | HIGH | 8.8 | 0.8% | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerabili... |
| CVE-2023-30624 | HIGH | 8.8 | 0.4% | Apr 27, 2023 | Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation o... |
| CVE-2023-30849 | HIGH | 8.8 | 0.8% | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerabili... |
| CVE-2023-30848 | HIGH | 8.8 | 0.7% | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API h... |
| CVE-2023-30847 | HIGH | 8.2 | 0.9% | Apr 27, 2023 | H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain ty... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now