2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26239 | MEDIUM | 5.5 | 0.2% | Oct 5, 2023 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible... |
| CVE-2023-26238 | MEDIUM | 5.5 | 0.2% | Oct 5, 2023 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by se... |
| CVE-2023-26237 | MEDIUM | 6.7 | 0.2% | Oct 5, 2023 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a ... |
| CVE-2023-26236 | HIGH | 7.8 | 0.1% | Oct 5, 2023 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGu... |
| CVE-2023-43877 | MEDIUM | 4.8 | 0.5% | Oct 4, 2023 | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via ... |
| CVE-2023-43321 | HIGH | 8.8 | 0.9% | Oct 4, 2023 | File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbi... |
| CVE-2023-40299 | HIGH | 7.8 | 0.4% | Oct 4, 2023 | Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC p... |
| CVE-2023-35803 | CRITICAL | 9.8 | 1.6% | Oct 4, 2023 | IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow. |
| CVE-2023-44389 | MEDIUM | 4.8 | 0.4% | Oct 4, 2023 | Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store ... |
| CVE-2023-43809 | HIGH | 7.5 | 0.9% | Oct 4, 2023 | Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft ... |
| CVE-2023-43805 | HIGH | 7.5 | 0.6% | Oct 4, 2023 | Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete ... |
| CVE-2023-43799 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize exte... |
| CVE-2023-43793 | HIGH | 7.5 | 0.7% | Oct 4, 2023 | Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user ca... |
| CVE-2023-41094 | CRITICAL | 9.8 | 0.6% | Oct 4, 2023 | TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Re... |
| CVE-2023-36619 | CRITICAL | 9.8 | 3.6% | Oct 4, 2023 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauth... |
| CVE-2023-36618 | HIGH | 8.8 | 3.4% | Oct 4, 2023 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-... |
| CVE-2023-44210 | MEDIUM | 5.5 | 0.3% | Oct 4, 2023 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr... |
| CVE-2023-44209 | HIGH | 7.8 | 0.3% | Oct 4, 2023 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec... |
| CVE-2023-44075 | MEDIUM | 5.4 | 0.5% | Oct 4, 2023 | Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a cr... |
| CVE-2023-42809 | HIGH | 8.8 | 1.0% | Oct 4, 2023 | Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received fr... |
| CVE-2023-42808 | MEDIUM | 6.1 | 0.5% | Oct 4, 2023 | Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create publ... |
| CVE-2023-42449 | HIGH | 8.1 | 0.9% | Oct 4, 2023 | Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head in... |
| CVE-2023-38538 | MEDIUM | 5 | 0.2% | Oct 4, 2023 | A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could ha... |
| CVE-2023-38537 | MEDIUM | 5.6 | 0.2% | Oct 4, 2023 | A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incomi... |
| CVE-2023-5399 | CRITICAL | 9.8 | 38.5% | Oct 4, 2023 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now