2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40376 | MEDIUM | 6.5 | 0.5% | Oct 4, 2023 | IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations cou... |
| CVE-2023-27433 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery... |
| CVE-2023-25025 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ... |
| CVE-2023-22515 | CRITICAL | 9.8 | 99.2% | Oct 4, 2023 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited... |
| CVE-2023-1832 | HIGH | 8.1 | 0.5% | Oct 4, 2023 | An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant... |
| CVE-2023-5373 | CRITICAL | 9.8 | 0.8% | Oct 4, 2023 | A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected i... |
| CVE-2023-4497 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr... |
| CVE-2023-4496 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr... |
| CVE-2023-4495 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cr... |
| CVE-2023-4494 | CRITICAL | 9.8 | 0.9% | Oct 4, 2023 | Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long us... |
| CVE-2023-4493 | MEDIUM | 5.4 | 0.4% | Oct 4, 2023 | Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects m... |
| CVE-2023-4492 | MEDIUM | 6.1 | 0.4% | Oct 4, 2023 | Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, mid... |
| CVE-2023-4491 | CRITICAL | 9.8 | 0.9% | Oct 4, 2023 | Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could ... |
| CVE-2023-4090 | MEDIUM | 6.1 | 0.3% | Oct 4, 2023 | Cross-site Scripting (XSS) reflected vulnerability on WideStand until 5.3.5 version, which generates one of the meta tag... |
| CVE-2023-4037 | MEDIUM | 5.5 | 0.3% | Oct 4, 2023 | Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local a... |
| CVE-2023-44208 | CRITICAL | 9.1 | 0.3% | Oct 4, 2023 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr... |
| CVE-2023-43261 | HIGH | 7.5 | 60.2% | Oct 4, 2023 | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensiti... |
| CVE-2023-3361 | HIGH | 7.5 | 0.5% | Oct 4, 2023 | A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as... |
| CVE-2023-3153 | MEDIUM | 5.3 | 1.0% | Oct 4, 2023 | A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could al... |
| CVE-2023-3038 | HIGH | 7.5 | 0.6% | Oct 4, 2023 | SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote atta... |
| CVE-2023-3037 | HIGH | 8.6 | 0.6% | Oct 4, 2023 | Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a re... |
| CVE-2023-22618 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users ... |
| CVE-2023-4997 | HIGH | 8.8 | 0.5% | Oct 4, 2023 | Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to cha... |
| CVE-2023-4586 | HIGH | 7.4 | 0.4% | Oct 4, 2023 | A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostna... |
| CVE-2023-3701 | HIGH | 8.8 | 0.6% | Oct 4, 2023 | Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerabili... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now