2023 CVE Vulnerabilities
31,399 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39732 | HIGH | 8.2 | 0.6% | Oct 25, 2023 | The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token a... |
| CVE-2023-39619 | HIGH | 7.5 | 1.1% | Oct 25, 2023 | ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpS... |
| CVE-2023-39231 | MEDIUM | 6.5 | 0.5% | Oct 25, 2023 | PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authenti... |
| CVE-2023-39219 | HIGH | 7.5 | 0.6% | Oct 25, 2023 | PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java ... |
| CVE-2023-38041 | HIGH | 7 | 0.7% | Oct 25, 2023 | A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a p... |
| CVE-2023-37913 | HIGH | 8.8 | 1.1% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver... |
| CVE-2023-37912 | HIGH | 8.8 | 1.2% | Oct 25, 2023 | XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior t... |
| CVE-2023-37911 | MEDIUM | 6.5 | 0.8% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver... |
| CVE-2023-37910 | HIGH | 8.1 | 0.6% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with t... |
| CVE-2023-37909 | HIGH | 8.8 | 1.6% | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver... |
| CVE-2023-37908 | CRITICAL | 9.6 | 1.1% | Oct 25, 2023 | XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cle... |
| CVE-2023-37283 | CRITICAL | 9.8 | 0.7% | Oct 25, 2023 | Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Iden... |
| CVE-2023-36085 | MEDIUM | 6.1 | 0.5% | Oct 25, 2023 | The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdent... |
| CVE-2023-34447 | MEDIUM | 6.1 | 0.7% | Oct 25, 2023 | iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, ... |
| CVE-2023-34446 | MEDIUM | 6.1 | 0.5% | Oct 25, 2023 | iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pa... |
| CVE-2023-34085 | MEDIUM | 4.3 | 0.5% | Oct 25, 2023 | When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user... |
| CVE-2023-34056 | MEDIUM | 4.3 | 0.7% | Oct 25, 2023 | vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privil... |
| CVE-2023-34048 | CRITICAL | 9.8 | 99.4% | Oct 25, 2023 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious a... |
| CVE-2023-31582 | HIGH | 7.5 | 0.6% | Oct 25, 2023 | jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less. |
| CVE-2023-31581 | CRITICAL | 9.8 | 0.8% | Oct 25, 2023 | Dromara Sureness before v1.0.8 was discovered to use a hardcoded key. |
| CVE-2023-31580 | MEDIUM | 5.9 | 0.5% | Oct 25, 2023 | light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authen... |
| CVE-2023-30912 | CRITICAL | 9.8 | 1.2% | Oct 25, 2023 | A remote code execution issue exists in HPE OneView. |
| CVE-2023-29973 | MEDIUM | 4.9 | 1.6% | Oct 25, 2023 | Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users ... |
| CVE-2023-27377 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application ... |
| CVE-2023-27376 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 an... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now