2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42004 | HIGH | 8.8 | 1.1% | Nov 28, 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute ... |
| CVE-2023-6151 | HIGH | 7.5 | 0.6% | Nov 28, 2023 | Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b... |
| CVE-2023-6150 | HIGH | 7.5 | 0.6% | Nov 28, 2023 | Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b... |
| CVE-2023-4667 | MEDIUM | 4.8 | 0.4% | Nov 28, 2023 | The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fie... |
| CVE-2023-34055 | MEDIUM | 6.5 | 1.2% | Nov 28, 2023 | In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially cra... |
| CVE-2023-34054 | HIGH | 7.5 | 0.9% | Nov 28, 2023 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a u... |
| CVE-2023-34053 | HIGH | 7.5 | 1.1% | Nov 28, 2023 | In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that m... |
| CVE-2023-4226 | HIGH | 8.8 | 2.4% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers wit... |
| CVE-2023-4225 | HIGH | 8.8 | 1.8% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers... |
| CVE-2023-4224 | HIGH | 8.8 | 1.8% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers ... |
| CVE-2023-4223 | HIGH | 8.8 | 1.8% | Nov 28, 2023 | Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers... |
| CVE-2023-4222 | HIGH | 8.8 | 3.5% | Nov 28, 2023 | Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to u... |
| CVE-2023-4221 | HIGH | 8.8 | 3.5% | Nov 28, 2023 | Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to up... |
| CVE-2023-4220 | MEDIUM | 6.1 | 76.1% | Nov 28, 2023 | Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in C... |
| CVE-2023-48023 | CRITICAL | 9.1 | 35.1% | Nov 28, 2023 | Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant becau... |
| CVE-2023-48022 | CRITICAL | 9.8 | 81.5% | Nov 28, 2023 | Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve... |
| CVE-2023-3545 | CRITICAL | 9.8 | 2.0% | Nov 28, 2023 | Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installation... |
| CVE-2023-3533 | CRITICAL | 9.8 | 2.7% | Nov 28, 2023 | Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20... |
| CVE-2023-3368 | CRITICAL | 9.8 | 68.9% | Nov 28, 2023 | Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated at... |
| CVE-2023-24023 | MEDIUM | 6.8 | 1.3% | Nov 28, 2023 | Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 t... |
| CVE-2023-6226 | MEDIUM | 4.3 | 0.5% | Nov 28, 2023 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in... |
| CVE-2023-6225 | MEDIUM | 5.4 | 0.5% | Nov 28, 2023 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2023-49075 | HIGH | 7.2 | 1.4% | Nov 28, 2023 | The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introdu... |
| CVE-2023-48713 | MEDIUM | 5.3 | 0.9% | Nov 28, 2023 | Knative Serving builds on Kubernetes to support deploying and serving of applications and functions as serverless contai... |
| CVE-2023-32065 | MEDIUM | 5.8 | 0.5% | Nov 28, 2023 | OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now