2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6206 | MEDIUM | 5.4 | 0.6% | Nov 21, 2023 | The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prom... |
| CVE-2023-6205 | MEDIUM | 6.5 | 0.9% | Nov 21, 2023 | It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to a... |
| CVE-2023-6204 | MEDIUM | 6.5 | 0.8% | Nov 21, 2023 | On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak m... |
| CVE-2023-49061 | MEDIUM | 6.1 | 0.3% | Nov 21, 2023 | An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerab... |
| CVE-2023-49060 | CRITICAL | 9.8 | 0.6% | Nov 21, 2023 | An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrer... |
| CVE-2023-48124 | MEDIUM | 5.4 | 0.6% | Nov 21, 2023 | Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email... |
| CVE-2023-6235 | HIGH | 7.8 | 0.3% | Nov 21, 2023 | An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1.... |
| CVE-2023-28802 | MEDIUM | 5.4 | 0.2% | Nov 21, 2023 | An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to d... |
| CVE-2023-5599 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x thr... |
| CVE-2023-5598 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ... |
| CVE-2023-5776 | HIGH | 8.8 | 0.3% | Nov 21, 2023 | The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2023-5553 | MEDIUM | 6.8 | 0.3% | Nov 21, 2023 | During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t... |
| CVE-2023-4424 | HIGH | 8.8 | 0.4% | Nov 21, 2023 | An malicious BLE device can cause buffer overflow by sending malformed advertising packet BLE device using Zephyr OS, le... |
| CVE-2023-4149 | CRITICAL | 9.8 | 1.1% | Nov 21, 2023 | A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system command... |
| CVE-2023-46935 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in u... |
| CVE-2023-21418 | HIGH | 7.1 | 0.7% | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to pat... |
| CVE-2023-21417 | HIGH | 7.1 | 0.7% | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnera... |
| CVE-2023-21416 | MEDIUM | 6.5 | 0.7% | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable t... |
| CVE-2023-45886 | HIGH | 7.5 | 1.4% | Nov 21, 2023 | The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending... |
| CVE-2023-42770 | CRITICAL | 9.8 | 0.9% | Nov 21, 2023 | Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an... |
| CVE-2023-6144 | MEDIUM | 4.8 | 0.4% | Nov 21, 2023 | Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any use... |
| CVE-2023-6142 | MEDIUM | 5.4 | 0.4% | Nov 21, 2023 | Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. Wi... |
| CVE-2023-40151 | CRITICAL | 9.8 | 1.1% | Nov 21, 2023 | When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK ... |
| CVE-2023-6199 | MEDIUM | 6.5 | 1.4% | Nov 20, 2023 | Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulne... |
| CVE-2023-48310 | HIGH | 7.5 | 1.1% | Nov 20, 2023 | TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtere... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now