2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42435 | HIGH | 8.8 | 0.2% | Oct 19, 2023 | The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to pe... |
| CVE-2023-41089 | HIGH | 8.8 | 0.5% | Oct 19, 2023 | The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to ... |
| CVE-2023-41088 | MEDIUM | 6.5 | 0.2% | Oct 19, 2023 | The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which ... |
| CVE-2023-40153 | MEDIUM | 6.1 | 0.3% | Oct 19, 2023 | The affected product is vulnerable to a cross-site scripting vulnerability, which could allow an attacker to access the... |
| CVE-2023-5059 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Santesoft Sante FFT Imaging lacks proper validation of user-supplied data when parsing DICOM files. This could lead... |
| CVE-2023-39431 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an ... |
| CVE-2023-38128 | HIGH | 7.8 | 0.7% | Oct 19, 2023 | An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specia... |
| CVE-2023-38127 | HIGH | 7.8 | 0.6% | Oct 19, 2023 | An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted docum... |
| CVE-2023-35986 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a sta... |
| CVE-2023-34366 | HIGH | 7.8 | 0.6% | Oct 19, 2023 | A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A special... |
| CVE-2023-45665 | — | — | — | Oct 19, 2023 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2023-45281 | MEDIUM | 6.1 | 0.4% | Oct 19, 2023 | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file. |
| CVE-2023-45278 | CRITICAL | 9.1 | 1.6% | Oct 19, 2023 | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbi... |
| CVE-2023-45277 | HIGH | 7.5 | 1.0% | Oct 19, 2023 | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of th... |
| CVE-2023-35126 | HIGH | 7.8 | 0.5% | Oct 19, 2023 | An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles... |
| CVE-2023-46033 | MEDIUM | 6.8 | 0.3% | Oct 19, 2023 | D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The... |
| CVE-2023-5654 | MEDIUM | 6.5 | 0.5% | Oct 19, 2023 | The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in ... |
| CVE-2023-46042 | CRITICAL | 9.8 | 22.6% | Oct 19, 2023 | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinf... |
| CVE-2023-43251 | HIGH | 7.8 | 0.5% | Oct 19, 2023 | XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this is... |
| CVE-2023-35187 | CRITICAL | 9.8 | 3.0% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerabil... |
| CVE-2023-35186 | HIGH | 8.8 | 2.2% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a... |
| CVE-2023-35185 | MEDIUM | 6.8 | 1.1% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM pri... |
| CVE-2023-35184 | CRITICAL | 9.8 | 1.4% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a... |
| CVE-2023-35183 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows au... |
| CVE-2023-35182 | CRITICAL | 9.8 | 2.4% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now