2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46326 | HIGH | 8.8 | 0.7% | Nov 30, 2023 | ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the sessio... |
| CVE-2023-42917 | HIGH | 8.8 | 9.4% | Nov 30, 2023 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1... |
| CVE-2023-42916 | MEDIUM | 6.5 | 18.0% | Nov 30, 2023 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2,... |
| CVE-2023-5909 | HIGH | 7.5 | 0.4% | Nov 30, 2023 | KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to conne... |
| CVE-2023-5908 | CRITICAL | 9.1 | 1.0% | Nov 30, 2023 | KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or l... |
| CVE-2023-49735 | HIGH | 7.5 | 1.4% | Nov 30, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not ... |
| CVE-2023-48894 | MEDIUM | 6.5 | 0.6% | Nov 30, 2023 | Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter ... |
| CVE-2023-47207 | CRITICAL | 9.8 | 16.6% | Nov 30, 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to... |
| CVE-2023-46690 | HIGH | 8.8 | 1.5% | Nov 30, 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any fi... |
| CVE-2023-39226 | CRITICAL | 9.8 | 1.2% | Nov 30, 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to... |
| CVE-2023-6442 | MEDIUM | 5.4 | 0.6% | Nov 30, 2023 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. ... |
| CVE-2023-6440 | MEDIUM | 5.4 | 0.6% | Nov 30, 2023 | A vulnerability was found in SourceCodester Book Borrower System 1.0 and classified as problematic. This issue affects s... |
| CVE-2023-47454 | HIGH | 7.8 | 0.3% | Nov 30, 2023 | An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated pri... |
| CVE-2023-47453 | HIGH | 7.8 | 0.3% | Nov 30, 2023 | An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges thr... |
| CVE-2023-47452 | HIGH | 7.8 | 0.5% | Nov 30, 2023 | An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msim... |
| CVE-2023-6439 | MEDIUM | 6.1 | 0.7% | Nov 30, 2023 | A vulnerability classified as problematic was found in ZenTao PMS 18.8. Affected by this vulnerability is an unknown fun... |
| CVE-2023-6376 | HIGH | 7.5 | 1.1% | Nov 30, 2023 | Henschen & Associates court document management software does not sufficiently randomize file names of cached documents,... |
| CVE-2023-6375 | HIGH | 7.5 | 1.0% | Nov 30, 2023 | Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthen... |
| CVE-2023-6354 | CRITICAL | 9.4 | 1.0% | Nov 30, 2023 | Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, a... |
| CVE-2023-6353 | CRITICAL | 9.4 | 1.0% | Nov 30, 2023 | Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, an... |
| CVE-2023-6352 | MEDIUM | 5.3 | 1.1% | Nov 30, 2023 | The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions i... |
| CVE-2023-6344 | MEDIUM | 5.3 | 0.9% | Nov 30, 2023 | Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using t... |
| CVE-2023-6343 | MEDIUM | 5.3 | 0.9% | Nov 30, 2023 | Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitiv... |
| CVE-2023-6342 | CRITICAL | 9.8 | 1.1% | Nov 30, 2023 | Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at le... |
| CVE-2023-6341 | MEDIUM | 5.3 | 0.9% | Nov 30, 2023 | Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now