2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7271 | MEDIUM | 5.5 | 0.1% | Jul 25, 2024 | Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect a... |
| CVE-2023-32471 | MEDIUM | 6 | 0.2% | Jul 24, 2024 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated mali... |
| CVE-2023-32466 | MEDIUM | 5.7 | 0.2% | Jul 24, 2024 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated mal... |
| CVE-2023-7268 | MEDIUM | 6.5 | 0.4% | Jul 19, 2024 | The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, a... |
| CVE-2023-6708 | MEDIUM | 5.4 | 0.3% | Jul 18, 2024 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all vers... |
| CVE-2023-43971 | MEDIUM | 6.1 | 0.4% | Jul 17, 2024 | Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode ... |
| CVE-2023-52291 | MEDIUM | 4.7 | 1.6% | Jul 17, 2024 | In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not str... |
| CVE-2023-7013 | MEDIUM | 4.7 | 0.2% | Jul 16, 2024 | Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potent... |
| CVE-2023-7011 | MEDIUM | 6.5 | 0.4% | Jul 16, 2024 | Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to... |
| CVE-2023-31456 | MEDIUM | 5.4 | 0.2% | Jul 16, 2024 | There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be ... |
| CVE-2023-52886 | MEDIUM | 6.4 | 0.3% | Jul 16, 2024 | In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descri... |
| CVE-2023-41916 | MEDIUM | 6.5 | 0.7% | Jul 15, 2024 | In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql ... |
| CVE-2023-39329 | MEDIUM | 6.5 | 0.6% | Jul 13, 2024 | A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a cra... |
| CVE-2023-39327 | MEDIUM | 4.3 | 0.5% | Jul 13, 2024 | A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuou... |
| CVE-2023-35006 | MEDIUM | 5.4 | 0.3% | Jul 10, 2024 | IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which ... |
| CVE-2023-33860 | MEDIUM | 5.3 | 0.2% | Jul 10, 2024 | IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may... |
| CVE-2023-33859 | MEDIUM | 5.3 | 0.4% | Jul 10, 2024 | IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM ... |
| CVE-2023-6813 | MEDIUM | 6.1 | 0.4% | Jul 10, 2024 | The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all v... |
| CVE-2023-50181 | MEDIUM | 6.5 | 0.3% | Jul 9, 2024 | An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 al... |
| CVE-2023-50179 | MEDIUM | 5.9 | 0.2% | Jul 9, 2024 | An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 al... |
| CVE-2023-39328 | MEDIUM | 5.5 | 0.2% | Jul 9, 2024 | A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protecti... |
| CVE-2023-52891 | MEDIUM | 5.3 | 0.5% | Jul 9, 2024 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (A... |
| CVE-2023-52238 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | A vulnerability has been identified in RUGGEDCOM RST2228 (All versions < V5.9.0), RUGGEDCOM RST2228P (All versions < V5.... |
| CVE-2023-3290 | MEDIUM | 5 | 0.3% | Jul 9, 2024 | A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the s... |
| CVE-2023-3289 | MEDIUM | 6.5 | 0.3% | Jul 9, 2024 | A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (incl... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now