2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43344 | MEDIUM | 5.4 | 0.6% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co... |
| CVE-2023-43342 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co... |
| CVE-2023-43341 | MEDIUM | 6.1 | 0.6% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via ... |
| CVE-2023-45823 | HIGH | 7.5 | 0.6% | Oct 19, 2023 | Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for... |
| CVE-2023-45822 | MEDIUM | 5.3 | 0.5% | Oct 19, 2023 | Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for... |
| CVE-2023-45821 | MEDIUM | 6.3 | 0.2% | Oct 19, 2023 | Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for... |
| CVE-2023-30132 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptog... |
| CVE-2023-30131 | CRITICAL | 9.8 | 0.8% | Oct 19, 2023 | An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege,... |
| CVE-2023-27795 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key. |
| CVE-2023-27793 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak ... |
| CVE-2023-27792 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions ... |
| CVE-2023-45376 | CRITICAL | 9.8 | 0.7% | Oct 19, 2023 | In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.... |
| CVE-2023-43492 | CRITICAL | 9.8 | 0.9% | Oct 19, 2023 | In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which ... |
| CVE-2023-40145 | HIGH | 8.8 | 1.2% | Oct 19, 2023 | In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to th... |
| CVE-2023-38584 | CRITICAL | 9.8 | 1.1% | Oct 19, 2023 | In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which... |
| CVE-2023-30633 | MEDIUM | 5.3 | 0.2% | Oct 19, 2023 | An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR... |
| CVE-2023-27791 | HIGH | 8.1 | 0.7% | Oct 19, 2023 | An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG. |
| CVE-2023-45992 | CRITICAL | 9.6 | 0.6% | Oct 19, 2023 | A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could... |
| CVE-2023-45826 | MEDIUM | 6.5 | 1.9% | Oct 19, 2023 | Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.... |
| CVE-2023-45825 | MEDIUM | 5.5 | 0.2% | Oct 19, 2023 | ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custo... |
| CVE-2023-45820 | MEDIUM | 6.5 | 0.7% | Oct 19, 2023 | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus insta... |
| CVE-2023-45809 | LOW | 2.7 | 0.5% | Oct 19, 2023 | Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for... |
| CVE-2023-45381 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform... |
| CVE-2023-43986 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component Configur... |
| CVE-2023-42666 | MEDIUM | 5.3 | 0.4% | Oct 19, 2023 | The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnera... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now