2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44470 | HIGH | 8.8 | 0.2% | Oct 10, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions. |
| CVE-2023-44241 | HIGH | 8.8 | 0.2% | Oct 10, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Keap Keap Landing Pages plugin <= 1.4.2 versions. |
| CVE-2023-30801 | CRITICAL | 9.8 | 0.9% | Oct 10, 2023 | All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The... |
| CVE-2023-5450 | HIGH | 7.8 | 0.1% | Oct 10, 2023 | An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an at... |
| CVE-2023-45226 | HIGH | 7.4 | 0.4% | Oct 10, 2023 | The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credent... |
| CVE-2023-45219 | MEDIUM | 4.4 | 0.2% | Oct 10, 2023 | Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allo... |
| CVE-2023-43788 | MEDIUM | 5.5 | 0.4% | Oct 10, 2023 | A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This ... |
| CVE-2023-43787 | HIGH | 7.8 | 0.4% | Oct 10, 2023 | A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a lo... |
| CVE-2023-43786 | MEDIUM | 5.5 | 0.5% | Oct 10, 2023 | A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local ... |
| CVE-2023-43785 | MEDIUM | 5.5 | 0.6% | Oct 10, 2023 | A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows ... |
| CVE-2023-43746 | HIGH | 8.7 | 0.4% | Oct 10, 2023 | When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance m... |
| CVE-2023-43611 | HIGH | 7.8 | 0.1% | Oct 10, 2023 | The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati... |
| CVE-2023-43485 | MEDIUM | 5.5 | 0.2% | Oct 10, 2023 | When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audi... |
| CVE-2023-42768 | HIGH | 7.2 | 0.5% | Oct 10, 2023 | When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's rol... |
| CVE-2023-41964 | MEDIUM | 6.5 | 0.2% | Oct 10, 2023 | The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Sof... |
| CVE-2023-41373 | CRITICAL | 9.9 | 2.4% | Oct 10, 2023 | A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker... |
| CVE-2023-41253 | MEDIUM | 5.5 | 0.2% | Oct 10, 2023 | When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintex... |
| CVE-2023-41085 | HIGH | 7.5 | 0.5% | Oct 10, 2023 | When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions... |
| CVE-2023-40542 | HIGH | 7.5 | 0.5% | Oct 10, 2023 | When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can ca... |
| CVE-2023-40537 | HIGH | 8.1 | 0.5% | Oct 10, 2023 | An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configurat... |
| CVE-2023-40534 | HIGH | 7.5 | 0.5% | Oct 10, 2023 | When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using th... |
| CVE-2023-39447 | MEDIUM | 4.4 | 0.2% | Oct 10, 2023 | When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.... |
| CVE-2023-44763 | MEDIUM | 5.4 | 0.6% | Oct 10, 2023 | Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cros... |
| CVE-2023-45601 | HIGH | 7.8 | 0.2% | Oct 10, 2023 | A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.262), Parasolid V35.1 (All versions < V35.1... |
| CVE-2023-45205 | HIGH | 7.8 | 0.2% | Oct 10, 2023 | A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is instal... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now