2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7282 | MEDIUM | 4.3 | 0.2% | Sep 23, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinc... |
| CVE-2023-7281 | MEDIUM | 4.3 | 0.2% | Sep 23, 2024 | Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perfor... |
| CVE-2023-46948 | MEDIUM | 5.4 | 0.4% | Sep 23, 2024 | A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attac... |
| CVE-2023-41611 | MEDIUM | 6.5 | 0.4% | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data. |
| CVE-2023-43753 | MEDIUM | 6.8 | 0.2% | Sep 16, 2024 | Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enabl... |
| CVE-2023-23904 | MEDIUM | 6.9 | 0.1% | Sep 16, 2024 | NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially en... |
| CVE-2023-22351 | MEDIUM | 6.9 | 0.1% | Sep 16, 2024 | Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable esca... |
| CVE-2023-3410 | MEDIUM | 5.4 | 0.3% | Sep 14, 2024 | The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up... |
| CVE-2023-44254 | MEDIUM | 6.5 | 0.5% | Sep 10, 2024 | An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.... |
| CVE-2023-49069 | MEDIUM | 6.9 | 0.4% | Sep 10, 2024 | A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mech... |
| CVE-2023-30755 | MEDIUM | 5.9 | 0.4% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP... |
| CVE-2023-2919 | MEDIUM | 4.3 | 0.2% | Sep 10, 2024 | The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. ... |
| CVE-2023-50883 | MEDIUM | 6.1 | 0.6% | Sep 9, 2024 | ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and theref... |
| CVE-2023-39333 | MEDIUM | 5.3 | 0.9% | Sep 7, 2024 | Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be ... |
| CVE-2023-30582 | MEDIUM | 5.3 | 0.6% | Sep 7, 2024 | A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the... |
| CVE-2023-51368 | MEDIUM | 6.5 | 0.3% | Sep 6, 2024 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
| CVE-2023-51366 | MEDIUM | 6.5 | 0.5% | Sep 6, 2024 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2023-50366 | MEDIUM | 4.8 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2023-52915 | MEDIUM | 5.5 | 0.2% | Sep 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af... |
| CVE-2023-51712 | MEDIUM | 4.7 | 0.3% | Sep 5, 2024 | An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem ... |
| CVE-2023-7279 | MEDIUM | 5.9 | 0.5% | Sep 2, 2024 | A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This... |
| CVE-2023-7256 | MEDIUM | 4.4 | 0.2% | Aug 31, 2024 | In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls ... |
| CVE-2023-49582 | MEDIUM | 5.5 | 0.3% | Aug 26, 2024 | Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to name... |
| CVE-2023-48957 | MEDIUM | 5.3 | 0.4% | Aug 25, 2024 | PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and ... |
| CVE-2023-6987 | MEDIUM | 6.1 | 0.3% | Aug 24, 2024 | The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now