2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47109 | HIGH | 8.1 | 0.8% | Nov 8, 2023 | PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that t... |
| CVE-2023-43570 | MEDIUM | 6.7 | 0.2% | Nov 8, 2023 | A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacke... |
| CVE-2023-43569 | MEDIUM | 6.7 | 0.2% | Nov 8, 2023 | A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with... |
| CVE-2023-43568 | MEDIUM | 4.4 | 0.2% | Nov 8, 2023 | A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a loc... |
| CVE-2023-43567 | MEDIUM | 6.7 | 0.2% | Nov 8, 2023 | A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a loca... |
| CVE-2023-36667 | HIGH | 7.5 | 1.0% | Nov 8, 2023 | Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal. |
| CVE-2023-46363 | MEDIUM | 5.5 | 0.3% | Nov 8, 2023 | jbig2enc v0.28 was discovered to contain a SEGV via jbig2_add_page in src/jbig2enc.cc:512. |
| CVE-2023-46362 | MEDIUM | 5.5 | 0.3% | Nov 8, 2023 | jbig2enc v0.28 was discovered to contain a heap-use-after-free via jbig2enc_auto_threshold_using_hash in src/jbig2enc.cc... |
| CVE-2023-45875 | HIGH | 7.5 | 0.7% | Nov 8, 2023 | An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node ... |
| CVE-2023-45857 | MEDIUM | 6.5 | 0.6% | Nov 8, 2023 | An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it i... |
| CVE-2023-29974 | CRITICAL | 9.8 | 1.8% | Nov 8, 2023 | An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requireme... |
| CVE-2023-0392 | MEDIUM | 6.7 | 0.2% | Nov 8, 2023 | The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execut... |
| CVE-2023-5996 | HIGH | 8.8 | 2.0% | Nov 8, 2023 | Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit hea... |
| CVE-2023-26221 | LOW | 3.9 | 0.2% | Nov 8, 2023 | The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marke... |
| CVE-2023-47231 | MEDIUM | 5.4 | 0.4% | Nov 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 version... |
| CVE-2023-47229 | MEDIUM | 5.4 | 0.4% | Nov 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 ver... |
| CVE-2023-47228 | MEDIUM | 4.8 | 0.4% | Nov 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions. |
| CVE-2023-47227 | MEDIUM | 4.8 | 0.4% | Nov 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one plac... |
| CVE-2023-47226 | MEDIUM | 4.8 | 0.4% | Nov 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Post Sliders & Post Grids plug... |
| CVE-2023-47223 | MEDIUM | 4.8 | 0.4% | Nov 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2... |
| CVE-2023-47190 | MEDIUM | 5.4 | 0.4% | Nov 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plu... |
| CVE-2023-47181 | MEDIUM | 4.8 | 0.4% | Nov 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions. |
| CVE-2023-3282 | MEDIUM | 6.7 | 0.2% | Nov 8, 2023 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linu... |
| CVE-2023-5913 | CRITICAL | 9.8 | 0.6% | Nov 8, 2023 | Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited ... |
| CVE-2023-5760 | HIGH | 7 | 0.2% | Nov 8, 2023 | A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now