2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46218 | MEDIUM | 6.5 | 1.7% | Dec 7, 2023 | This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than w... |
| CVE-2023-6566 | MEDIUM | 6.5 | 0.5% | Dec 7, 2023 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-46354 | HIGH | 7.5 | 0.6% | Dec 6, 2023 | In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can d... |
| CVE-2023-46353 | CRITICAL | 9.8 | 0.8% | Dec 6, 2023 | In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL inj... |
| CVE-2023-49096 | HIGH | 8.8 | 1.3% | Dec 6, 2023 | Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument inj... |
| CVE-2023-48123 | HIGH | 8.8 | 67.8% | Dec 6, 2023 | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitra... |
| CVE-2023-46751 | HIGH | 7.5 | 1.5% | Dec 6, 2023 | An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows r... |
| CVE-2023-6393 | MEDIUM | 5.3 | 0.6% | Dec 6, 2023 | A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the ... |
| CVE-2023-45285 | HIGH | 7.5 | 1.1% | Dec 6, 2023 | Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the... |
| CVE-2023-39326 | MEDIUM | 5.3 | 1.2% | Dec 6, 2023 | A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read man... |
| CVE-2023-39539 | HIGH | 7.8 | 0.6% | Dec 6, 2023 | AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dange... |
| CVE-2023-39538 | HIGH | 7.8 | 0.2% | Dec 6, 2023 | AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dange... |
| CVE-2023-36655 | CRITICAL | 9.8 | 1.0% | Dec 6, 2023 | The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a r... |
| CVE-2023-48859 | HIGH | 8.8 | 1.2% | Dec 6, 2023 | TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows atta... |
| CVE-2023-6288 | HIGH | 7.8 | 0.3% | Dec 6, 2023 | Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLI... |
| CVE-2023-32268 | HIGH | 7.2 | 0.7% | Dec 6, 2023 | Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credent... |
| CVE-2023-6514 | HIGH | 8.8 | 0.3% | Dec 6, 2023 | The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successf... |
| CVE-2023-6459 | MEDIUM | 5.3 | 0.5% | Dec 6, 2023 | Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the ch... |
| CVE-2023-6458 | CRITICAL | 9.8 | 0.6% | Dec 6, 2023 | Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perf... |
| CVE-2023-6273 | MEDIUM | 5.3 | 0.4% | Dec 6, 2023 | Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerabi... |
| CVE-2023-49248 | MEDIUM | 5.5 | 0.2% | Dec 6, 2023 | Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause u... |
| CVE-2023-49247 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect... |
| CVE-2023-49246 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affec... |
| CVE-2023-49245 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect s... |
| CVE-2023-49244 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect s... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now