2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29063 | LOW | 2.4 | 0.2% | Nov 28, 2023 | The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat ... |
| CVE-2023-29062 | LOW | 3.8 | 0.3% | Nov 28, 2023 | The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials u... |
| CVE-2023-29061 | MEDIUM | 5.2 | 0.4% | Nov 28, 2023 | There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can pote... |
| CVE-2023-45539 | HIGH | 8.2 | 1.5% | Nov 28, 2023 | HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive info... |
| CVE-2023-30590 | HIGH | 7.5 | 1.5% | Nov 28, 2023 | The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, th... |
| CVE-2023-30588 | MEDIUM | 5.3 | 1.2% | Nov 28, 2023 | When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect ter... |
| CVE-2023-29060 | MEDIUM | 5.7 | 0.3% | Nov 28, 2023 | The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited... |
| CVE-2023-49078 | MEDIUM | 6.1 | 0.5% | Nov 28, 2023 | raptor-web is a CMS for game server communities that can be used to host information and keep track of players. In versi... |
| CVE-2023-48121 | MEDIUM | 5.3 | 0.8% | Nov 28, 2023 | An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 2023040... |
| CVE-2023-42504 | MEDIUM | 6.5 | 1.1% | Nov 28, 2023 | An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports,... |
| CVE-2023-40056 | HIGH | 8.8 | 4.8% | Nov 28, 2023 | SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be expl... |
| CVE-2023-48848 | HIGH | 7.5 | 0.9% | Nov 28, 2023 | An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server ... |
| CVE-2023-45286 | MEDIUM | 5.9 | 0.7% | Nov 28, 2023 | A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered... |
| CVE-2023-42505 | MEDIUM | 4.3 | 1.0% | Nov 28, 2023 | An authenticated user with read permissions on database connections metadata could potentially access sensitive informat... |
| CVE-2023-42502 | MEDIUM | 5.4 | 0.8% | Nov 28, 2023 | An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing t... |
| CVE-2023-41264 | CRITICAL | 9.8 | 1.0% | Nov 28, 2023 | Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on dep... |
| CVE-2023-49062 | HIGH | 7.5 | 0.6% | Nov 28, 2023 | Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulatio... |
| CVE-2023-46589 | HIGH | 7.5 | 2.7% | Nov 28, 2023 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 throug... |
| CVE-2023-49314 | HIGH | 7.8 | 4.3% | Nov 28, 2023 | Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection ag... |
| CVE-2023-49313 | CRITICAL | 9.8 | 1.3% | Nov 28, 2023 | A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unaut... |
| CVE-2023-6239 | HIGH | 8.8 | 0.6% | Nov 28, 2023 | Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specif... |
| CVE-2023-48042 | MEDIUM | 6.1 | 0.5% | Nov 28, 2023 | Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote at... |
| CVE-2023-6359 | MEDIUM | 6.1 | 0.4% | Nov 28, 2023 | A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could ... |
| CVE-2023-6201 | HIGH | 8.8 | 1.6% | Nov 28, 2023 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Comp... |
| CVE-2023-5981 | MEDIUM | 5.9 | 1.3% | Nov 28, 2023 | A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from resp... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now