2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45909 | MEDIUM | 6.1 | 0.3% | Oct 18, 2023 | zzzcms v2.2.0 was discovered to contain an open redirect vulnerability. |
| CVE-2023-37502 | HIGH | 8.8 | 0.5% | Oct 18, 2023 | HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that c... |
| CVE-2023-45958 | MEDIUM | 6.1 | 0.3% | Oct 18, 2023 | Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pa... |
| CVE-2023-45814 | MEDIUM | 5.3 | 0.4% | Oct 18, 2023 | Bunkum is an open-source protocol-agnostic request server for custom game servers. First, a little bit of background. So... |
| CVE-2023-45812 | HIGH | 7.5 | 0.7% | Oct 18, 2023 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that us... |
| CVE-2023-45146 | CRITICAL | 10 | 1.0% | Oct 18, 2023 | XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework ... |
| CVE-2023-43801 | HIGH | 7.1 | 0.3% | Oct 18, 2023 | Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/... |
| CVE-2023-43800 | HIGH | 7.8 | 0.2% | Oct 18, 2023 | Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/t... |
| CVE-2023-45813 | HIGH | 7.5 | 0.8% | Oct 18, 2023 | Torbot is an open source tor network intelligence tool. In affected versions the `torbot.modules.validators.validate_lin... |
| CVE-2023-45145 | LOW | 3.6 | 0.4% | Oct 18, 2023 | Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusti... |
| CVE-2023-43803 | HIGH | 7.1 | 0.3% | Oct 18, 2023 | Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/... |
| CVE-2023-43802 | HIGH | 7.8 | 0.4% | Oct 18, 2023 | Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` ... |
| CVE-2023-4601 | CRITICAL | 9.8 | 0.6% | Oct 18, 2023 | A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosur... |
| CVE-2023-35663 | HIGH | 7.5 | 0.3% | Oct 18, 2023 | In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This coul... |
| CVE-2023-35656 | HIGH | 7.5 | 0.3% | Oct 18, 2023 | In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds c... |
| CVE-2023-26300 | HIGH | 7.8 | 0.2% | Oct 18, 2023 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow e... |
| CVE-2023-45912 | HIGH | 7.5 | 0.6% | Oct 18, 2023 | WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers ... |
| CVE-2023-45911 | CRITICAL | 9.8 | 0.8% | Oct 18, 2023 | An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user wi... |
| CVE-2023-30911 | HIGH | 7.5 | 0.5% | Oct 18, 2023 | HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service. |
| CVE-2023-20261 | MEDIUM | 6.5 | 0.5% | Oct 18, 2023 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve... |
| CVE-2023-5642 | CRITICAL | 9.8 | 16.7% | Oct 18, 2023 | Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, whi... |
| CVE-2023-46009 | HIGH | 7.8 | 0.3% | Oct 18, 2023 | gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c. |
| CVE-2023-45383 | HIGH | 7.5 | 0.6% | Oct 18, 2023 | In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest c... |
| CVE-2023-43250 | HIGH | 7.8 | 0.6% | Oct 18, 2023 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attacker... |
| CVE-2023-5631 | MEDIUM | 5.4 | 70.9% | Oct 18, 2023 | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now