2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5391 | CRITICAL | 9.8 | 0.8% | Oct 4, 2023 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary c... |
| CVE-2023-42824 | HIGH | 7.8 | 0.9% | Oct 4, 2023 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may ... |
| CVE-2023-42448 | HIGH | 8.1 | 0.8% | Oct 4, 2023 | Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the cont... |
| CVE-2023-3576 | MEDIUM | 5.5 | 0.3% | Oct 4, 2023 | A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image fil... |
| CVE-2023-3428 | MEDIUM | 5.5 | 0.3% | Oct 4, 2023 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local atta... |
| CVE-2023-39191 | HIGH | 8.2 | 0.5% | Oct 4, 2023 | An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of... |
| CVE-2023-38701 | CRITICAL | 9.1 | 0.9% | Oct 4, 2023 | Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to co... |
| CVE-2023-27121 | MEDIUM | 6.1 | 21.3% | Oct 4, 2023 | A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasa... |
| CVE-2023-5402 | CRITICAL | 9.8 | 0.7% | Oct 4, 2023 | A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the trans... |
| CVE-2023-5371 | MEDIUM | 6.5 | 0.5% | Oct 4, 2023 | RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection... |
| CVE-2023-43804 | HIGH | 8.1 | 1.2% | Oct 4, 2023 | urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or pro... |
| CVE-2023-20259 | HIGH | 7.5 | 0.6% | Oct 4, 2023 | A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, rem... |
| CVE-2023-20235 | HIGH | 8.8 | 0.5% | Oct 4, 2023 | A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastr... |
| CVE-2023-20101 | CRITICAL | 9.8 | 2.4% | Oct 4, 2023 | A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected de... |
| CVE-2023-43838 | HIGH | 7.8 | 0.6% | Oct 4, 2023 | An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code ... |
| CVE-2023-5113 | MEDIUM | 6.1 | 0.3% | Oct 4, 2023 | Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to W... |
| CVE-2023-4380 | MEDIUM | 6.3 | 0.5% | Oct 4, 2023 | A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, th... |
| CVE-2023-4237 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the priv... |
| CVE-2023-40559 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin... |
| CVE-2023-3971 | MEDIUM | 5.4 | 0.7% | Oct 4, 2023 | An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture c... |
| CVE-2023-3665 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable th... |
| CVE-2023-5374 | CRITICAL | 9.8 | 0.7% | Oct 4, 2023 | A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by thi... |
| CVE-2023-4567 | — | — | — | Oct 4, 2023 | Rejected reason: Issue has been found to be non-reproducible, therefore not a viable flaw. |
| CVE-2023-40684 | MEDIUM | 5.4 | 0.3% | Oct 4, 2023 | IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. T... |
| CVE-2023-40561 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now