2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27148 | MEDIUM | 4.8 | 0.4% | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to... |
| CVE-2023-46288 | MEDIUM | 4.3 | 1.4% | Oct 23, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Air... |
| CVE-2023-43045 | HIGH | 7.5 | 0.7% | Oct 23, 2023 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized action... |
| CVE-2023-38722 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulne... |
| CVE-2023-46331 | MEDIUM | 5.5 | 0.2% | Oct 23, 2023 | WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fa... |
| CVE-2023-37532 | MEDIUM | 4.3 | 0.5% | Oct 23, 2023 | HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files o... |
| CVE-2023-46332 | MEDIUM | 5.5 | 0.3% | Oct 23, 2023 | WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault. |
| CVE-2023-46122 | HIGH | 7.1 | 0.3% | Oct 23, 2023 | sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of... |
| CVE-2023-43067 | MEDIUM | 6.5 | 0.4% | Oct 23, 2023 | Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploi... |
| CVE-2023-43066 | HIGH | 7.8 | 0.2% | Oct 23, 2023 | Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local atta... |
| CVE-2023-5718 | MEDIUM | 4.3 | 0.2% | Oct 23, 2023 | The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessa... |
| CVE-2023-46127 | MEDIUM | 5.4 | 37.0% | Oct 23, 2023 | Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated clien... |
| CVE-2023-43074 | HIGH | 7.5 | 0.5% | Oct 23, 2023 | Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially... |
| CVE-2023-43065 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can expl... |
| CVE-2023-42295 | HIGH | 8.8 | 0.9% | Oct 23, 2023 | An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service... |
| CVE-2023-28805 | CRITICAL | 9.8 | 0.3% | Oct 23, 2023 | An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue ... |
| CVE-2023-28804 | MEDIUM | 5.3 | 0.2% | Oct 23, 2023 | An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing ... |
| CVE-2023-28803 | MEDIUM | 6.5 | 0.3% | Oct 23, 2023 | An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on ... |
| CVE-2023-28797 | HIGH | 7.3 | 0.2% | Oct 23, 2023 | Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk.... |
| CVE-2023-28796 | HIGH | 7.8 | 0.2% | Oct 23, 2023 | Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injectio... |
| CVE-2023-28795 | HIGH | 7.8 | 0.1% | Oct 23, 2023 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process.... |
| CVE-2023-28793 | HIGH | 7.8 | 0.3% | Oct 23, 2023 | Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. Th... |
| CVE-2023-5246 | HIGH | 8.8 | 0.8% | Oct 23, 2023 | Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074,... |
| CVE-2023-45802 | MEDIUM | 5.9 | 3.0% | Oct 23, 2023 | When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were... |
| CVE-2023-43622 | HIGH | 7.5 | 70.6% | Oct 23, 2023 | An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now