2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41101 | CRITICAL | 9.8 | 1.9% | Nov 17, 2023 | An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not ... |
| CVE-2023-39548 | HIGH | 8.8 | 0.7% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39547 | HIGH | 8.8 | 0.6% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39546 | HIGH | 8.8 | 0.6% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39545 | HIGH | 8.8 | 0.7% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-39544 | HIGH | 8.8 | 0.6% | Nov 17, 2023 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP... |
| CVE-2023-38324 | MEDIUM | 5.3 | 0.7% | Nov 17, 2023 | An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authent... |
| CVE-2023-38322 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference th... |
| CVE-2023-38320 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer derefere... |
| CVE-2023-38316 | CRITICAL | 9.8 | 1.1% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, a... |
| CVE-2023-38315 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer deref... |
| CVE-2023-38314 | MEDIUM | 6.5 | 0.9% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthent... |
| CVE-2023-38313 | HIGH | 7.5 | 1.0% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can b... |
| CVE-2023-48659 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing. |
| CVE-2023-48658 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, un... |
| CVE-2023-48657 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters. |
| CVE-2023-48656 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses. |
| CVE-2023-48655 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filt... |
| CVE-2023-47675 | HIGH | 7.2 | 1.0% | Nov 17, 2023 | CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary ... |
| CVE-2023-47283 | MEDIUM | 4.9 | 1.2% | Nov 17, 2023 | Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrati... |
| CVE-2023-42428 | MEDIUM | 6.5 | 1.3% | Nov 17, 2023 | Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrati... |
| CVE-2023-38130 | HIGH | 8.1 | 0.4% | Nov 17, 2023 | Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to d... |
| CVE-2023-48649 | MEDIUM | 5.4 | 0.6% | Nov 17, 2023 | Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name. |
| CVE-2023-48648 | CRITICAL | 9.8 | 1.2% | Nov 17, 2023 | Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insec... |
| CVE-2023-48031 | CRITICAL | 9.8 | 1.4% | Nov 17, 2023 | OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attac... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now