2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50423 | CRITICAL | 9.8 | 1.1% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an... |
| CVE-2023-50422 | CRITICAL | 9.8 | 1.4% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17... |
| CVE-2023-49583 | CRITICAL | 9.8 | 1.1% | Dec 12, 2023 | SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions a... |
| CVE-2023-49581 | CRITICAL | 9.4 | 0.5% | Dec 12, 2023 | SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise b... |
| CVE-2023-36649 | CRITICAL | 9.1 | 0.9% | Dec 12, 2023 | Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows re... |
| CVE-2023-50245 | CRITICAL | 9.8 | 1.1% | Dec 11, 2023 | OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overf... |
| CVE-2023-49418 | CRITICAL | 9.8 | 0.9% | Dec 11, 2023 | TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules. |
| CVE-2023-49417 | CRITICAL | 9.8 | 0.9% | Dec 11, 2023 | TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg. |
| CVE-2023-6181 | CRITICAL | 9.8 | 0.4% | Dec 11, 2023 | An oversight in BCB handling of reboot reason that allows for persistent code execution |
| CVE-2023-48425 | CRITICAL | 9.8 | 0.4% | Dec 11, 2023 | U-Boot vulnerability resulting in persistent Code Execution |
| CVE-2023-48424 | CRITICAL | 9.8 | 0.3% | Dec 11, 2023 | U-Boot shell vulnerability resulting in Privilege escalation in a production device |
| CVE-2023-48417 | CRITICAL | 9.8 | 0.3% | Dec 11, 2023 | Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application |
| CVE-2023-6658 | CRITICAL | 9.8 | 0.8% | Dec 10, 2023 | A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerabil... |
| CVE-2023-6657 | CRITICAL | 9.8 | 0.9% | Dec 10, 2023 | A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affec... |
| CVE-2023-6655 | CRITICAL | 9.8 | 3.8% | Dec 10, 2023 | A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some ... |
| CVE-2023-6652 | CRITICAL | 9.8 | 0.9% | Dec 10, 2023 | A vulnerability was found in code-projects Matrimonial Site 1.0. It has been declared as critical. Affected by this vuln... |
| CVE-2023-6651 | CRITICAL | 9.8 | 0.9% | Dec 10, 2023 | A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unkn... |
| CVE-2023-6648 | CRITICAL | 9.8 | 1.0% | Dec 10, 2023 | A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. Th... |
| CVE-2023-6647 | CRITICAL | 9.8 | 1.0% | Dec 10, 2023 | A vulnerability, which was classified as critical, has been found in AMTT HiBOS 1.0. Affected by this issue is some unkn... |
| CVE-2023-50429 | CRITICAL | 9.1 | 0.7% | Dec 9, 2023 | IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection. |
| CVE-2023-47254 | CRITICAL | 9.8 | 2.2% | Dec 9, 2023 | An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbit... |
| CVE-2023-46932 | CRITICAL | 9.8 | 1.1% | Dec 9, 2023 | Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitra... |
| CVE-2023-6394 | CRITICAL | 9.1 | 0.8% | Dec 9, 2023 | A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission spe... |
| CVE-2023-46498 | CRITICAL | 9.8 | 1.3% | Dec 8, 2023 | An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execu... |
| CVE-2023-6619 | CRITICAL | 9.8 | 0.8% | Dec 8, 2023 | A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been rated as critical. Affecte... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now