2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49243 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerabi... |
| CVE-2023-49242 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect ... |
| CVE-2023-49241 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may... |
| CVE-2023-49240 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect servi... |
| CVE-2023-49239 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affec... |
| CVE-2023-46773 | CRITICAL | 9.8 | 0.5% | Dec 6, 2023 | Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege... |
| CVE-2023-46688 | MEDIUM | 6.1 | 0.5% | Dec 6, 2023 | Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect user... |
| CVE-2023-45210 | MEDIUM | 4.3 | 0.5% | Dec 6, 2023 | Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticate... |
| CVE-2023-44113 | HIGH | 7.5 | 0.4% | Dec 6, 2023 | Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful explo... |
| CVE-2023-44099 | HIGH | 7.5 | 0.5% | Dec 6, 2023 | Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause ... |
| CVE-2023-34439 | MEDIUM | 5.4 | 0.4% | Dec 6, 2023 | Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited... |
| CVE-2023-48849 | CRITICAL | 9.8 | 1.3% | Dec 6, 2023 | Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitr... |
| CVE-2023-49897 | HIGH | 8.8 | 50.7% | Dec 6, 2023 | An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version ... |
| CVE-2023-2861 | HIGH | 7.1 | 0.4% | Dec 6, 2023 | A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit openin... |
| CVE-2023-6527 | MEDIUM | 6.1 | 0.4% | Dec 6, 2023 | The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER h... |
| CVE-2023-26154 | MEDIUM | 5.9 | 1.0% | Dec 6, 2023 | Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubn... |
| CVE-2023-22524 | CRITICAL | 9.8 | 24.7% | Dec 6, 2023 | Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An att... |
| CVE-2023-22523 | HIGH | 8.8 | 11.1% | Dec 6, 2023 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with ... |
| CVE-2023-22522 | HIGH | 8.8 | 12.8% | Dec 6, 2023 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject u... |
| CVE-2023-41268 | CRITICAL | 9.8 | 0.7% | Dec 6, 2023 | Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. Th... |
| CVE-2023-40053 | MEDIUM | 5 | 0.8% | Dec 6, 2023 | A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file ... |
| CVE-2023-6512 | MEDIUM | 6.5 | 1.3% | Dec 6, 2023 | Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to pote... |
| CVE-2023-6511 | MEDIUM | 4.3 | 0.9% | Dec 6, 2023 | Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Aut... |
| CVE-2023-6510 | HIGH | 8.8 | 1.0% | Dec 6, 2023 | Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user t... |
| CVE-2023-6509 | HIGH | 8.8 | 1.0% | Dec 6, 2023 | Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a us... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now