2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47610 | CRITICAL | 9.8 | 1.7% | Nov 9, 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow ... |
| CVE-2023-45885 | MEDIUM | 5.4 | 0.4% | Nov 9, 2023 | Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary ... |
| CVE-2023-45884 | MEDIUM | 6.5 | 0.3% | Nov 9, 2023 | Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view se... |
| CVE-2023-45284 | MEDIUM | 5.3 | 0.9% | Nov 9, 2023 | On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed ... |
| CVE-2023-45283 | HIGH | 7.5 | 2.8% | Nov 9, 2023 | The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a... |
| CVE-2023-47110 | MEDIUM | 5.3 | 0.4% | Nov 9, 2023 | blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store ... |
| CVE-2023-46894 | HIGH | 7.5 | 0.5% | Nov 9, 2023 | An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm. |
| CVE-2023-46743 | MEDIUM | 4.3 | 0.5% | Nov 9, 2023 | application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on... |
| CVE-2023-36688 | MEDIUM | 4.8 | 0.4% | Nov 9, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versio... |
| CVE-2023-25994 | HIGH | 8.8 | 0.3% | Nov 9, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.4.2 versions. |
| CVE-2023-6039 | MEDIUM | 5.5 | 0.3% | Nov 9, 2023 | A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb... |
| CVE-2023-47373 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications... |
| CVE-2023-47372 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifi... |
| CVE-2023-47370 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to ... |
| CVE-2023-47368 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications ... |
| CVE-2023-43791 | HIGH | 8.8 | 1.2% | Nov 9, 2023 | Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability... |
| CVE-2023-41138 | MEDIUM | 6.7 | 0.2% | Nov 9, 2023 | The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissio... |
| CVE-2023-41137 | CRITICAL | 9.8 | 0.3% | Nov 9, 2023 | Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engine... |
| CVE-2023-40055 | HIGH | 8.8 | 2.1% | Nov 9, 2023 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vu... |
| CVE-2023-40054 | HIGH | 8.8 | 3.0% | Nov 9, 2023 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vu... |
| CVE-2023-4612 | CRITICAL | 9.8 | 0.9% | Nov 9, 2023 | Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allo... |
| CVE-2023-47369 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifi... |
| CVE-2023-47367 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notificatio... |
| CVE-2023-47366 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications... |
| CVE-2023-47365 | MEDIUM | 6.5 | 0.4% | Nov 9, 2023 | The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notific... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now