2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43902 | CRITICAL | 9.8 | 0.8% | Nov 14, 2023 | Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attacker... |
| CVE-2023-43901 | HIGH | 7.5 | 0.4% | Nov 14, 2023 | Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to ... |
| CVE-2023-43900 | MEDIUM | 6.5 | 0.6% | Nov 14, 2023 | Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized a... |
| CVE-2023-42326 | HIGH | 8.8 | 64.0% | Nov 14, 2023 | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the inte... |
| CVE-2023-6006 | MEDIUM | 6.7 | 0.4% | Nov 14, 2023 | This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. A... |
| CVE-2023-42327 | MEDIUM | 5.4 | 55.4% | Nov 14, 2023 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a cr... |
| CVE-2023-42325 | MEDIUM | 5.4 | 57.9% | Nov 14, 2023 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a cr... |
| CVE-2023-31754 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin pan... |
| CVE-2023-46446 | MEDIUM | 6.8 | 0.9% | Nov 14, 2023 | An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet inject... |
| CVE-2023-46445 | MEDIUM | 5.9 | 0.6% | Nov 14, 2023 | An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-mi... |
| CVE-2023-45560 | HIGH | 7.5 | 0.7% | Nov 14, 2023 | An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel acce... |
| CVE-2023-45558 | HIGH | 7.5 | 0.7% | Nov 14, 2023 | An issue in Golden v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. |
| CVE-2023-47629 | HIGH | 8 | 0.5% | Nov 14, 2023 | DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restr... |
| CVE-2023-47628 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default s... |
| CVE-2023-42480 | MEDIUM | 5.3 | 0.5% | Nov 14, 2023 | The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functional... |
| CVE-2023-41366 | MEDIUM | 5.3 | 0.6% | Nov 14, 2023 | Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.... |
| CVE-2023-31403 | HIGH | 8 | 0.4% | Nov 14, 2023 | SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB sh... |
| CVE-2023-6115 | — | — | — | Nov 14, 2023 | Rejected reason: DUPLICATE CVE |
| CVE-2023-6107 | — | — | — | Nov 14, 2023 | Rejected reason: Accidental Request. |
| CVE-2023-6106 | — | — | — | Nov 14, 2023 | Rejected reason: Accidental request. |
| CVE-2023-6092 | — | — | — | Nov 14, 2023 | Rejected reason: DUPLICATE, accidental request. |
| CVE-2023-6089 | — | — | — | Nov 14, 2023 | Rejected reason: Accidental Request. |
| CVE-2023-6088 | — | — | — | Nov 14, 2023 | Rejected reason: Accidental Request. |
| CVE-2023-6087 | — | — | — | Nov 14, 2023 | Rejected reason: Accidental Request. |
| CVE-2023-6086 | — | — | — | Nov 14, 2023 | Rejected reason: Accidental request. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now