2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6112 | HIGH | 8.8 | 30.3% | Nov 15, 2023 | Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit h... |
| CVE-2023-5997 | HIGH | 8.8 | 1.0% | Nov 15, 2023 | Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially e... |
| CVE-2023-6079 | — | — | — | Nov 15, 2023 | Rejected reason: appears to be a duplicate of CVE-2023-40206 |
| CVE-2023-34982 | HIGH | 7.1 | 0.2% | Nov 15, 2023 | This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges t... |
| CVE-2023-33873 | HIGH | 7.8 | 0.2% | Nov 15, 2023 | This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileg... |
| CVE-2023-48089 | HIGH | 8.8 | 1.3% | Nov 15, 2023 | xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save. |
| CVE-2023-48088 | MEDIUM | 5.4 | 0.4% | Nov 15, 2023 | xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage. |
| CVE-2023-48087 | MEDIUM | 5.4 | 0.4% | Nov 15, 2023 | xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/l... |
| CVE-2023-5720 | HIGH | 7.5 | 0.8% | Nov 15, 2023 | A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing cer... |
| CVE-2023-5676 | MEDIUM | 5.9 | 0.4% | Nov 15, 2023 | In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentatio... |
| CVE-2023-5245 | CRITICAL | 9.8 | 1.2% | Nov 15, 2023 | FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the a... |
| CVE-2023-4602 | MEDIUM | 6.1 | 0.7% | Nov 15, 2023 | The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in ... |
| CVE-2023-23549 | LOW | 2.7 | 0.6% | Nov 15, 2023 | Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial deni... |
| CVE-2023-34062 | HIGH | 7.5 | 1.1% | Nov 15, 2023 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can se... |
| CVE-2023-46672 | MEDIUM | 5.5 | 0.3% | Nov 15, 2023 | An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstanc... |
| CVE-2023-6133 | MEDIUM | 4.9 | 0.9% | Nov 15, 2023 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'for... |
| CVE-2023-4889 | MEDIUM | 5.4 | 0.4% | Nov 15, 2023 | The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in version... |
| CVE-2023-47586 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 ... |
| CVE-2023-47585 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a ... |
| CVE-2023-47584 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a... |
| CVE-2023-47583 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | Multiple out-of-bounds read vulnerabilities exist in TELLUS Simulator V4.0.17.0 and earlier. If a user opens a specially... |
| CVE-2023-47582 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | Access of uninitialized pointer vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earli... |
| CVE-2023-47581 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | Out-of-bounds read vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user... |
| CVE-2023-47580 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | Multiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and ea... |
| CVE-2023-47446 | MEDIUM | 5.4 | 0.4% | Nov 15, 2023 | Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname param... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now