2023 CVE Vulnerabilities
31,402 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26319 | HIGH | 7.2 | 0.9% | Oct 11, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Route... |
| CVE-2023-26318 | HIGH | 7.2 | 0.5% | Oct 11, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Over... |
| CVE-2023-5511 | HIGH | 8.8 | 0.3% | Oct 11, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3. |
| CVE-2023-45194 | MEDIUM | 4.3 | 0.2% | Oct 11, 2023 | Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-... |
| CVE-2023-44689 | MEDIUM | 4.3 | 0.4% | Oct 11, 2023 | e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versio... |
| CVE-2023-26220 | MEDIUM | 5.4 | 0.3% | Oct 10, 2023 | The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploita... |
| CVE-2023-36127 | HIGH | 7.5 | 0.6% | Oct 10, 2023 | User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where ... |
| CVE-2023-36126 | MEDIUM | 6.1 | 0.4% | Oct 10, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Sc... |
| CVE-2023-45312 | HIGH | 8.8 | 1.5% | Oct 10, 2023 | In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access... |
| CVE-2023-45648 | MEDIUM | 5.3 | 5.8% | Oct 10, 2023 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 throug... |
| CVE-2023-31096 | HIGH | 7.8 | 0.5% | Oct 10, 2023 | An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There ... |
| CVE-2023-5497 | HIGH | 8.8 | 0.7% | Oct 10, 2023 | A vulnerability classified as critical has been found in Tongda OA 2017 11.10. Affected is an unknown function of the fi... |
| CVE-2023-4309 | CRITICAL | 9.8 | 1.1% | Oct 10, 2023 | Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. T... |
| CVE-2023-45129 | MEDIUM | 4.9 | 1.2% | Oct 10, 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0... |
| CVE-2023-42795 | MEDIUM | 5.3 | 2.2% | Oct 10, 2023 | Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M... |
| CVE-2023-42794 | MEDIUM | 5.9 | 1.9% | Oct 10, 2023 | Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat ... |
| CVE-2023-41774 | HIGH | 8.1 | 1.3% | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-41773 | HIGH | 8.1 | 1.3% | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-41772 | HIGH | 7.8 | 11.8% | Oct 10, 2023 | Win32k Elevation of Privilege Vulnerability |
| CVE-2023-41771 | HIGH | 8.1 | 1.3% | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-41770 | HIGH | 8.1 | 1.3% | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-41769 | HIGH | 8.1 | 1.3% | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-41768 | HIGH | 8.1 | 1.3% | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-41767 | HIGH | 8.1 | 1.3% | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-41766 | HIGH | 7.8 | 1.3% | Oct 10, 2023 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now