2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6508 | HIGH | 8.8 | 1.0% | Dec 6, 2023 | Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit ... |
| CVE-2023-48940 | MEDIUM | 5.4 | 0.5% | Dec 6, 2023 | A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary ... |
| CVE-2023-48930 | CRITICAL | 9.8 | 1.2% | Dec 6, 2023 | xinhu xinhuoa 2.2.1 contains a File upload vulnerability. |
| CVE-2023-28876 | MEDIUM | 4.3 | 0.5% | Dec 6, 2023 | A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delet... |
| CVE-2023-28875 | MEDIUM | 5.4 | 0.4% | Dec 6, 2023 | A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code ... |
| CVE-2023-24547 | MEDIUM | 6.5 | 0.3% | Dec 6, 2023 | On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in cl... |
| CVE-2023-49283 | MEDIUM | 5.3 | 2.2% | Dec 5, 2023 | microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which cont... |
| CVE-2023-49282 | MEDIUM | 5.3 | 2.2% | Dec 5, 2023 | msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained t... |
| CVE-2023-5970 | HIGH | 8.8 | 0.9% | Dec 5, 2023 | Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an ... |
| CVE-2023-49297 | HIGH | 7.8 | 0.5% | Dec 5, 2023 | PyDrive2 is a wrapper library of google-api-python-client that simplifies many common Google Drive API V2 tasks. Unsafe ... |
| CVE-2023-46736 | MEDIUM | 6.5 | 0.4% | Dec 5, 2023 | EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Req... |
| CVE-2023-44221 | HIGH | 7.2 | 74.9% | Dec 5, 2023 | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated att... |
| CVE-2023-6448 | CRITICAL | 9.8 | 2.1% | Dec 5, 2023 | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative passwo... |
| CVE-2023-46674 | HIGH | 7.8 | 0.2% | Dec 5, 2023 | An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration prope... |
| CVE-2023-45287 | HIGH | 7.5 | 1.3% | Dec 5, 2023 | Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was ... |
| CVE-2023-45085 | LOW | 3.3 | 0.2% | Dec 5, 2023 | An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct ini... |
| CVE-2023-45084 | MEDIUM | 6.1 | 0.2% | Dec 5, 2023 | An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause ... |
| CVE-2023-45083 | MEDIUM | 4.4 | 0.2% | Dec 5, 2023 | An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authentic... |
| CVE-2023-44298 | MEDIUM | 6.8 | 0.2% | Dec 5, 2023 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security v... |
| CVE-2023-44297 | MEDIUM | 6.8 | 0.3% | Dec 5, 2023 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security v... |
| CVE-2023-6357 | HIGH | 8.8 | 1.0% | Dec 5, 2023 | A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system l... |
| CVE-2023-6180 | MEDIUM | 5.3 | 0.6% | Dec 5, 2023 | The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consump... |
| CVE-2023-49448 | HIGH | 8.8 | 0.4% | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete. |
| CVE-2023-49447 | HIGH | 8.8 | 0.4% | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update. |
| CVE-2023-49446 | HIGH | 8.8 | 0.4% | Dec 5, 2023 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now