2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44002 | — | — | — | Oct 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-46862 | MEDIUM | 4.7 | 0.2% | Oct 29, 2023 | An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_ur... |
| CVE-2023-40685 | HIGH | 7.8 | 0.1% | Oct 29, 2023 | Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability... |
| CVE-2023-5840 | HIGH | 8.8 | 0.7% | Oct 29, 2023 | Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9. |
| CVE-2023-5839 | HIGH | 7.8 | 0.3% | Oct 29, 2023 | Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. |
| CVE-2023-5838 | CRITICAL | 9.8 | 0.5% | Oct 29, 2023 | Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9. |
| CVE-2023-46858 | MEDIUM | 5.4 | 0.6% | Oct 29, 2023 | Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodl... |
| CVE-2023-43041 | MEDIUM | 4.9 | 0.5% | Oct 29, 2023 | IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain ... |
| CVE-2023-40686 | HIGH | 7.8 | 0.1% | Oct 29, 2023 | Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability... |
| CVE-2023-5837 | MEDIUM | 6.1 | 0.4% | Oct 28, 2023 | A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affect... |
| CVE-2023-5836 | CRITICAL | 9.8 | 0.4% | Oct 28, 2023 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been rated as critical. Affected by this is... |
| CVE-2023-46854 | MEDIUM | 6.1 | 0.4% | Oct 28, 2023 | Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature... |
| CVE-2023-45897 | MEDIUM | 5.5 | 0.4% | Oct 28, 2023 | exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set. |
| CVE-2023-5835 | MEDIUM | 6.1 | 0.4% | Oct 28, 2023 | A vulnerability classified as problematic was found in hu60t hu60wap6. Affected by this vulnerability is the function ma... |
| CVE-2023-5426 | HIGH | 7.5 | 0.5% | Oct 28, 2023 | The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2023-5425 | HIGH | 8.8 | 0.5% | Oct 28, 2023 | The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2023-46215 | HIGH | 7.5 | 1.2% | Oct 28, 2023 | Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensi... |
| CVE-2023-46570 | CRITICAL | 9.8 | 0.9% | Oct 28, 2023 | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h... |
| CVE-2023-46569 | CRITICAL | 9.8 | 0.9% | Oct 28, 2023 | An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-d... |
| CVE-2023-46468 | HIGH | 7.8 | 0.5% | Oct 28, 2023 | An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the cus... |
| CVE-2023-46467 | MEDIUM | 5.4 | 0.5% | Oct 28, 2023 | Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via... |
| CVE-2023-43322 | HIGH | 8.8 | 1.1% | Oct 28, 2023 | ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.... |
| CVE-2023-46587 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted... |
| CVE-2023-5834 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, int... |
| CVE-2023-46490 | MEDIUM | 6.5 | 1.4% | Oct 27, 2023 | SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actio... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now