2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32064 | MEDIUM | 4.3 | 0.5% | Nov 28, 2023 | OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can acce... |
| CVE-2023-32063 | MEDIUM | 5 | 0.5% | Nov 28, 2023 | OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access... |
| CVE-2023-6219 | HIGH | 7.2 | 1.2% | Nov 28, 2023 | The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the... |
| CVE-2023-5960 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.5... |
| CVE-2023-5797 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t... |
| CVE-2023-5650 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, ... |
| CVE-2023-4398 | HIGH | 7.5 | 0.9% | Nov 28, 2023 | An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ... |
| CVE-2023-4397 | MEDIUM | 4.4 | 0.2% | Nov 28, 2023 | A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, US... |
| CVE-2023-47503 | CRITICAL | 9.8 | 1.3% | Nov 28, 2023 | An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the log... |
| CVE-2023-37926 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware ve... |
| CVE-2023-37925 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t... |
| CVE-2023-35139 | MEDIUM | 6.1 | 0.5% | Nov 28, 2023 | A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.3... |
| CVE-2023-35136 | MEDIUM | 5.5 | 0.2% | Nov 28, 2023 | An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 throug... |
| CVE-2023-30585 | HIGH | 7.5 | 1.5% | Nov 28, 2023 | A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows u... |
| CVE-2023-47437 | MEDIUM | 5.4 | 0.5% | Nov 28, 2023 | A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting... |
| CVE-2023-29770 | HIGH | 8.8 | 0.9% | Nov 28, 2023 | In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file w... |
| CVE-2023-49145 | MEDIUM | 5.4 | 1.2% | Nov 27, 2023 | Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user ... |
| CVE-2023-48188 | CRITICAL | 9.8 | 1.3% | Nov 27, 2023 | SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrar... |
| CVE-2023-46480 | CRITICAL | 9.8 | 1.6% | Nov 27, 2023 | An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ... |
| CVE-2023-46355 | MEDIUM | 5.3 | 0.5% | Nov 27, 2023 | In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal informati... |
| CVE-2023-46349 | CRITICAL | 9.8 | 0.8% | Nov 27, 2023 | In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop,... |
| CVE-2023-42366 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. |
| CVE-2023-42365 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar functio... |
| CVE-2023-42364 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk patte... |
| CVE-2023-5885 | MEDIUM | 6.5 | 1.1% | Nov 27, 2023 | The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now