2023 CVE Vulnerabilities
31,399 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46345 | HIGH | 7.5 | 0.6% | Oct 26, 2023 | Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c. |
| CVE-2023-43906 | MEDIUM | 6.1 | 0.4% | Oct 26, 2023 | Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability. |
| CVE-2023-43905 | HIGH | 7.5 | 0.4% | Oct 26, 2023 | Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecifi... |
| CVE-2023-30969 | MEDIUM | 6.5 | 0.4% | Oct 26, 2023 | The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authen... |
| CVE-2023-30967 | HIGH | 7.5 | 0.6% | Oct 26, 2023 | Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unaut... |
| CVE-2023-46584 | CRITICAL | 9.8 | 0.7% | Oct 25, 2023 | SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker t... |
| CVE-2023-46583 | MEDIUM | 6.1 | 0.5% | Oct 25, 2023 | Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attack... |
| CVE-2023-46232 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | era-compiler-vyper is the EraVM Vyper compiler for zkSync Era, a layer 2 rollup that uses zero-knowledge proofs to scale... |
| CVE-2023-38849 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. |
| CVE-2023-38848 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET r... |
| CVE-2023-38847 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET reque... |
| CVE-2023-38846 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. |
| CVE-2023-38845 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via craf... |
| CVE-2023-46233 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker th... |
| CVE-2023-46137 | MEDIUM | 5.3 | 0.8% | Oct 25, 2023 | Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP r... |
| CVE-2023-46134 | CRITICAL | 9.8 | 0.8% | Oct 25, 2023 | D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to v... |
| CVE-2023-46133 | CRITICAL | 9.1 | 0.4% | Oct 25, 2023 | CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF... |
| CVE-2023-45137 | MEDIUM | 5.4 | 0.6% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.plat... |
| CVE-2023-5574 | HIGH | 7 | 0.5% | Oct 25, 2023 | A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy confi... |
| CVE-2023-5380 | MEDIUM | 4.7 | 0.7% | Oct 25, 2023 | A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy config... |
| CVE-2023-5367 | HIGH | 7.8 | 0.6% | Oct 25, 2023 | A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buff... |
| CVE-2023-5044 | HIGH | 8.8 | 56.6% | Oct 25, 2023 | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. |
| CVE-2023-5043 | HIGH | 8.8 | 2.2% | Oct 25, 2023 | Ingress nginx annotation injection causes arbitrary command execution. |
| CVE-2023-46424 | CRITICAL | 9.8 | 1.9% | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-46423 | CRITICAL | 9.8 | 1.9% | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now