2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4931 | HIGH | 7.8 | 0.2% | Nov 27, 2023 | Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execu... |
| CVE-2023-4590 | CRITICAL | 9.8 | 1.1% | Nov 27, 2023 | Buffer overflow vulnerability in Frhed hex editor, affecting version 1.6.0. This vulnerability could allow an attacker t... |
| CVE-2023-5871 | MEDIUM | 5.3 | 0.9% | Nov 27, 2023 | A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such a... |
| CVE-2023-5607 | HIGH | 7.2 | 0.9% | Nov 27, 2023 | An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extensio... |
| CVE-2023-43701 | MEDIUM | 5.4 | 1.0% | Nov 27, 2023 | Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious acto... |
| CVE-2023-42501 | MEDIUM | 4.3 | 0.9% | Nov 27, 2023 | Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and ... |
| CVE-2023-40610 | HIGH | 8.8 | 1.3% | Nov 27, 2023 | Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the d... |
| CVE-2023-6254 | HIGH | 7.5 | 0.7% | Nov 27, 2023 | A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send b... |
| CVE-2023-6202 | MEDIUM | 4.3 | 0.4% | Nov 27, 2023 | Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker w... |
| CVE-2023-49068 | HIGH | 7.5 | 1.1% | Nov 27, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects A... |
| CVE-2023-48369 | MEDIUM | 5.3 | 0.6% | Nov 27, 2023 | Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to differe... |
| CVE-2023-48268 | HIGH | 7.5 | 0.7% | Nov 27, 2023 | Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards... |
| CVE-2023-47168 | MEDIUM | 6.1 | 0.4% | Nov 27, 2023 | Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user cli... |
| CVE-2023-45223 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a me... |
| CVE-2023-43754 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink prev... |
| CVE-2023-40703 | HIGH | 7.5 | 0.7% | Nov 27, 2023 | Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a... |
| CVE-2023-35075 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowi... |
| CVE-2023-47865 | MEDIUM | 4.3 | 0.4% | Nov 27, 2023 | Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. ... |
| CVE-2023-25632 | MEDIUM | 5.5 | 0.2% | Nov 27, 2023 | The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open ... |
| CVE-2023-6313 | MEDIUM | 6.1 | 0.6% | Nov 27, 2023 | A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vul... |
| CVE-2023-6312 | HIGH | 7.2 | 0.8% | Nov 27, 2023 | A vulnerability was found in SourceCodester Loan Management System 1.0. It has been classified as critical. Affected is ... |
| CVE-2023-6311 | HIGH | 7.2 | 0.8% | Nov 27, 2023 | A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects th... |
| CVE-2023-6310 | HIGH | 7.2 | 0.8% | Nov 27, 2023 | A vulnerability has been found in SourceCodester Loan Management System 1.0 and classified as critical. This vulnerabili... |
| CVE-2023-6309 | CRITICAL | 9.8 | 4.2% | Nov 27, 2023 | A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknow... |
| CVE-2023-6308 | HIGH | 8.8 | 1.0% | Nov 27, 2023 | A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management Sys... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now