2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5365 | CRITICAL | 9.8 | 0.6% | Oct 9, 2023 | HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure. |
| CVE-2023-44400 | HIGH | 7.8 | 0.3% | Oct 9, 2023 | Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain... |
| CVE-2023-41047 | MEDIUM | 6.5 | 0.6% | Oct 9, 2023 | OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability th... |
| CVE-2023-30910 | MEDIUM | 5.4 | 0.3% | Oct 9, 2023 | HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP r... |
| CVE-2023-44393 | MEDIUM | 6.1 | 1.3% | Oct 9, 2023 | Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS)... |
| CVE-2023-44378 | MEDIUM | 5.5 | 0.2% | Oct 9, 2023 | gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit... |
| CVE-2023-43643 | MEDIUM | 6.1 | 0.5% | Oct 9, 2023 | AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to versio... |
| CVE-2023-41660 | HIGH | 8.8 | 0.3% | Oct 9, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WPSynchro WP Synchro plugin <= 1.9.1 versions. |
| CVE-2023-36820 | MEDIUM | 6.5 | 0.4% | Oct 9, 2023 | Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, ... |
| CVE-2023-25822 | MEDIUM | 6.5 | 0.5% | Oct 9, 2023 | ReportPortal is an AI-powered test automation platform. Prior to version 5.10.0 of the `com.epam.reportportal:service-ap... |
| CVE-2023-5103 | MEDIUM | 4.3 | 0.5% | Oct 9, 2023 | Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to pot... |
| CVE-2023-5102 | MEDIUM | 5.3 | 0.6% | Oct 9, 2023 | Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable... |
| CVE-2023-5101 | MEDIUM | 5.3 | 0.6% | Oct 9, 2023 | Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to dow... |
| CVE-2023-5100 | MEDIUM | 6.5 | 0.4% | Oct 9, 2023 | Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retriev... |
| CVE-2023-43698 | MEDIUM | 6.1 | 0.5% | Oct 9, 2023 | Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an un... |
| CVE-2023-43697 | MEDIUM | 6.5 | 0.6% | Oct 9, 2023 | Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the ... |
| CVE-2023-45248 | HIGH | 7.3 | 0.2% | Oct 9, 2023 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2023-45247 | HIGH | 7.1 | 0.2% | Oct 9, 2023 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr... |
| CVE-2023-43700 | HIGH | 7.5 | 0.6% | Oct 9, 2023 | Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that... |
| CVE-2023-43699 | HIGH | 7.5 | 0.7% | Oct 9, 2023 | Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker ... |
| CVE-2023-43696 | CRITICAL | 9.8 | 0.6% | Oct 9, 2023 | Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary file... |
| CVE-2023-5333 | MEDIUM | 6.5 | 0.5% | Oct 9, 2023 | Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources... |
| CVE-2023-5331 | MEDIUM | 5.3 | 0.3% | Oct 9, 2023 | Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exp... |
| CVE-2023-5330 | HIGH | 7.5 | 0.5% | Oct 9, 2023 | Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a s... |
| CVE-2023-45613 | CRITICAL | 9.1 | 0.3% | Oct 9, 2023 | In JetBrains Ktor before 2.3.5 server certificates were not verified |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now