2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48051 | HIGH | 7.5 | 0.2% | Nov 20, 2023 | An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption pad... |
| CVE-2023-48192 | HIGH | 7.8 | 0.4% | Nov 20, 2023 | An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracero... |
| CVE-2023-48176 | CRITICAL | 9.8 | 0.9% | Nov 20, 2023 | An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jw... |
| CVE-2023-6178 | MEDIUM | 6.5 | 0.8% | Nov 20, 2023 | An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing applicatio... |
| CVE-2023-6062 | MEDIUM | 6.5 | 1.0% | Nov 20, 2023 | An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on t... |
| CVE-2023-47311 | MEDIUM | 6.1 | 0.4% | Nov 20, 2023 | An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking. |
| CVE-2023-47172 | HIGH | 7.8 | 0.2% | Nov 20, 2023 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Ser... |
| CVE-2023-46471 | MEDIUM | 5.4 | 0.6% | Nov 20, 2023 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi... |
| CVE-2023-46470 | MEDIUM | 5.4 | 0.6% | Nov 20, 2023 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi... |
| CVE-2023-48111 | HIGH | 7.5 | 0.8% | Nov 20, 2023 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentContro... |
| CVE-2023-48110 | HIGH | 7.5 | 0.8% | Nov 20, 2023 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControl... |
| CVE-2023-48109 | HIGH | 7.5 | 0.8% | Nov 20, 2023 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentCon... |
| CVE-2023-47417 | MEDIUM | 6.1 | 0.5% | Nov 20, 2023 | Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows att... |
| CVE-2023-46990 | CRITICAL | 9.8 | 1.5% | Nov 20, 2023 | Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a c... |
| CVE-2023-38823 | CRITICAL | 9.8 | 1.2% | Nov 20, 2023 | Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to exec... |
| CVE-2023-5799 | MEDIUM | 5.4 | 0.5% | Nov 20, 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing ... |
| CVE-2023-5652 | CRITICAL | 9.8 | 63.7% | Nov 20, 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not esca... |
| CVE-2023-5651 | MEDIUM | 5.4 | 0.3% | Nov 20, 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensu... |
| CVE-2023-5640 | CRITICAL | 9.8 | 1.0% | Nov 20, 2023 | The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statem... |
| CVE-2023-5610 | MEDIUM | 5.4 | 0.4% | Nov 20, 2023 | The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user ... |
| CVE-2023-5609 | MEDIUM | 6.1 | 0.4% | Nov 20, 2023 | The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it... |
| CVE-2023-5509 | MEDIUM | 5.4 | 0.5% | Nov 20, 2023 | The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in use... |
| CVE-2023-5343 | MEDIUM | 4.8 | 0.5% | Nov 20, 2023 | The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-5340 | CRITICAL | 9.8 | 1.2% | Nov 20, 2023 | The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX actio... |
| CVE-2023-5140 | MEDIUM | 6.1 | 0.4% | Nov 20, 2023 | The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now