2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44486 | — | — | — | Oct 31, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-44485 | — | — | — | Oct 31, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-44484 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstNam... |
| CVE-2023-46485 | CRITICAL | 9.8 | 1.2% | Oct 31, 2023 | An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracero... |
| CVE-2023-46484 | CRITICAL | 9.8 | 1.2% | Oct 31, 2023 | An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg ... |
| CVE-2023-43295 | LOW | 3.5 | 0.2% | Oct 31, 2023 | Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a lo... |
| CVE-2023-3955 | HIGH | 8.8 | 3.4% | Oct 31, 2023 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat... |
| CVE-2023-3676 | HIGH | 8.8 | 11.7% | Oct 31, 2023 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat... |
| CVE-2023-39610 | MEDIUM | 6.5 | 0.3% | Oct 31, 2023 | An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Ser... |
| CVE-2023-20886 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a ... |
| CVE-2023-41377 | — | — | — | Oct 31, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2023-45955 | HIGH | 7.5 | 0.6% | Oct 31, 2023 | An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write bind... |
| CVE-2023-37832 | HIGH | 7.5 | 0.6% | Oct 31, 2023 | A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute forc... |
| CVE-2023-37831 | MEDIUM | 5.3 | 0.5% | Oct 31, 2023 | An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server re... |
| CVE-2023-43796 | MEDIUM | 5.3 | 0.9% | Oct 31, 2023 | Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote ... |
| CVE-2023-5739 | HIGH | 7.8 | 0.2% | Oct 31, 2023 | Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege. |
| CVE-2023-46723 | HIGH | 7.5 | 0.4% | Oct 31, 2023 | lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable t... |
| CVE-2023-46722 | MEDIUM | 6.1 | 0.5% | Oct 31, 2023 | The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulne... |
| CVE-2023-46256 | CRITICAL | 9.8 | 0.6% | Oct 31, 2023 | PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a hea... |
| CVE-2023-46255 | MEDIUM | 6.5 | 0.4% | Oct 31, 2023 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per... |
| CVE-2023-46250 | MEDIUM | 5.5 | 0.2% | Oct 31, 2023 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 ... |
| CVE-2023-46249 | CRITICAL | 9.8 | 0.7% | Oct 31, 2023 | authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has... |
| CVE-2023-46248 | HIGH | 8.8 | 1.1% | Oct 31, 2023 | Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 ar... |
| CVE-2023-46245 | HIGH | 7.2 | 1.5% | Oct 31, 2023 | Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Templ... |
| CVE-2023-46240 | HIGH | 7.5 | 0.6% | Oct 31, 2023 | CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a d... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now