2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46239 | HIGH | 7.5 | 0.8% | Oct 31, 2023 | quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by seri... |
| CVE-2023-46993 | CRITICAL | 9.8 | 1.5% | Oct 31, 2023 | In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable ... |
| CVE-2023-46992 | HIGH | 7.5 | 0.5% | Oct 31, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral ... |
| CVE-2023-46237 | MEDIUM | 5.3 | 0.5% | Oct 31, 2023 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint... |
| CVE-2023-46236 | HIGH | 7.5 | 0.5% | Oct 31, 2023 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-si... |
| CVE-2023-46235 | MEDIUM | 6.1 | 0.3% | Oct 31, 2023 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a... |
| CVE-2023-42658 | HIGH | 7.8 | 0.3% | Oct 31, 2023 | Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profi... |
| CVE-2023-42425 | CRITICAL | 9.8 | 0.9% | Oct 31, 2023 | An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensit... |
| CVE-2023-40050 | HIGH | 8.8 | 1.2% | Oct 31, 2023 | Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec... |
| CVE-2023-37966 | CRITICAL | 9.8 | 0.5% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech Us... |
| CVE-2023-37243 | HIGH | 7.8 | 0.2% | Oct 31, 2023 | The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM w... |
| CVE-2023-36508 | CRITICAL | 9.8 | 0.6% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contac... |
| CVE-2023-35879 | CRITICAL | 9.8 | 0.6% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Produc... |
| CVE-2023-33927 | CRITICAL | 9.8 | 0.7% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple... |
| CVE-2023-31212 | CRITICAL | 9.8 | 0.8% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database... |
| CVE-2023-24410 | CRITICAL | 9.8 | 0.6% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPM... |
| CVE-2023-22518 | CRITICAL | 9.8 | 100.0% | Oct 31, 2023 | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz... |
| CVE-2023-5519 | MEDIUM | 4.3 | 0.2% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke... |
| CVE-2023-5458 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG file... |
| CVE-2023-5360 | CRITICAL | 9.8 | 81.7% | Oct 31, 2023 | The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which... |
| CVE-2023-5307 | MEDIUM | 6.1 | 0.5% | Oct 31, 2023 | The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, whic... |
| CVE-2023-5243 | MEDIUM | 4.8 | 0.4% | Oct 31, 2023 | The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could a... |
| CVE-2023-5238 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2023-5237 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes be... |
| CVE-2023-5229 | MEDIUM | 4.8 | 0.4% | Oct 31, 2023 | The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high priv... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now