2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5789 | MEDIUM | 4.8 | 0.5% | Oct 26, 2023 | A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown fu... |
| CVE-2023-5624 | HIGH | 7.2 | 0.5% | Oct 26, 2023 | Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow a... |
| CVE-2023-5623 | HIGH | 7.8 | 0.2% | Oct 26, 2023 | NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary... |
| CVE-2023-5622 | HIGH | 8.8 | 0.5% | Oct 26, 2023 | Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORI... |
| CVE-2023-46666 | MEDIUM | 6.5 | 0.4% | Oct 26, 2023 | An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepo... |
| CVE-2023-45317 | HIGH | 8.8 | 0.2% | Oct 26, 2023 | The application interface allows users to perform certain actions via HTTP requests without performing any validity ch... |
| CVE-2023-45228 | MEDIUM | 6.5 | 0.4% | Oct 26, 2023 | The application suffers from improper access control when editing users. A user with read permissions can manipulate ... |
| CVE-2023-43208 | CRITICAL | 9.8 | 82.7% | Oct 26, 2023 | NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that ... |
| CVE-2023-42769 | CRITICAL | 9.8 | 0.8% | Oct 26, 2023 | The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker ... |
| CVE-2023-41966 | HIGH | 8.8 | 0.6% | Oct 26, 2023 | The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileg... |
| CVE-2023-5787 | HIGH | 8.8 | 0.7% | Oct 26, 2023 | A vulnerability was found in Shaanxi Chanming Education Technology Score Query System 5.0. It has been rated as critical... |
| CVE-2023-5786 | HIGH | 8.8 | 0.8% | Oct 26, 2023 | A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability... |
| CVE-2023-5785 | HIGH | 7.5 | 0.6% | Oct 26, 2023 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This... |
| CVE-2023-5784 | CRITICAL | 9.8 | 0.7% | Oct 26, 2023 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by t... |
| CVE-2023-46450 | MEDIUM | 5.4 | 0.4% | Oct 26, 2023 | Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the ... |
| CVE-2023-46449 | HIGH | 8.8 | 0.8% | Oct 26, 2023 | Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbit... |
| CVE-2023-46238 | MEDIUM | 5.4 | 0.4% | Oct 26, 2023 | ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various i... |
| CVE-2023-46234 | HIGH | 7.5 | 0.5% | Oct 26, 2023 | browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based... |
| CVE-2023-45869 | CRITICAL | 9 | 0.8% | Oct 26, 2023 | ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a hi... |
| CVE-2023-45868 | HIGH | 8.1 | 1.1% | Oct 26, 2023 | The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high... |
| CVE-2023-45867 | MEDIUM | 6.5 | 0.9% | Oct 26, 2023 | ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the S... |
| CVE-2023-5783 | HIGH | 7.5 | 0.5% | Oct 26, 2023 | A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability i... |
| CVE-2023-5782 | CRITICAL | 9.8 | 0.7% | Oct 26, 2023 | A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown funct... |
| CVE-2023-46090 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions. |
| CVE-2023-41096 | MEDIUM | 6.1 | 0.1% | Oct 26, 2023 | Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High module... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now