2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0109 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability all... |
| CVE-2023-4134 | MEDIUM | 5.5 | 0.2% | Nov 14, 2024 | A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device... |
| CVE-2023-34049 | MEDIUM | 6.7 | 0.2% | Nov 14, 2024 | The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force ... |
| CVE-2023-38920 | MEDIUM | 4.8 | 0.3% | Nov 13, 2024 | Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary co... |
| CVE-2023-44255 | MEDIUM | 4.1 | 0.5% | Nov 12, 2024 | An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnal... |
| CVE-2023-1932 | MEDIUM | 6.1 | 0.5% | Nov 7, 2024 | A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.... |
| CVE-2023-29122 | MEDIUM | 6.7 | 0.2% | Nov 5, 2024 | Under certain conditions, access to service libraries is granted to account they should not have access to. |
| CVE-2023-29116 | MEDIUM | 4.3 | 0.2% | Nov 5, 2024 | Under certain conditions, through a request directed to the Waybox Enel X web management application, information like W... |
| CVE-2023-29115 | MEDIUM | 6.5 | 0.3% | Nov 5, 2024 | In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service... |
| CVE-2023-29114 | MEDIUM | 5.7 | 0.2% | Nov 5, 2024 | System logs could be accessed through web management application due to a lack of access control. An attacker can obta... |
| CVE-2023-52920 | MEDIUM | 5.5 | 0.2% | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from st... |
| CVE-2023-34445 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible f... |
| CVE-2023-34444 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possib... |
| CVE-2023-34443 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (X... |
| CVE-2023-52045 | MEDIUM | 6.1 | 0.3% | Oct 31, 2024 | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vuln... |
| CVE-2023-5816 | MEDIUM | 4.9 | 0.5% | Oct 30, 2024 | The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and inclu... |
| CVE-2023-26248 | MEDIUM | 5.3 | 0.2% | Oct 25, 2024 | The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information fo... |
| CVE-2023-50355 | MEDIUM | 5.3 | 0.2% | Oct 23, 2024 | HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information t... |
| CVE-2023-52919 | MEDIUM | 5.5 | 0.2% | Oct 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix possible NULL pointer dereference in ... |
| CVE-2023-52918 | MEDIUM | 5.5 | 0.2% | Oct 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() retu... |
| CVE-2023-6243 | MEDIUM | 4.3 | 0.2% | Oct 19, 2024 | The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge... |
| CVE-2023-6058 | MEDIUM | 6.8 | 0.2% | Oct 18, 2024 | A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the pr... |
| CVE-2023-49567 | MEDIUM | 6.8 | 0.2% | Oct 18, 2024 | A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product inc... |
| CVE-2023-39593 | MEDIUM | 5.6 | 0.7% | Oct 17, 2024 | Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary comma... |
| CVE-2023-32266 | MEDIUM | 5.3 | 0.2% | Oct 16, 2024 | Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclu... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now