2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3512 | HIGH | 7.5 | 0.6% | Oct 4, 2023 | Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploit... |
| CVE-2023-37995 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ... |
| CVE-2023-2809 | CRITICAL | 9.8 | 0.4% | Oct 4, 2023 | Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a ... |
| CVE-2023-2422 | HIGH | 7.1 | 0.4% | Oct 4, 2023 | A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does ... |
| CVE-2023-25980 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Re... |
| CVE-2023-25788 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Saphali Saphali Woocommerce Lite plugin <= 1.8.13 versions. |
| CVE-2023-25489 | HIGH | 8.8 | 0.2% | Oct 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 ver... |
| CVE-2023-1584 | HIGH | 7.5 | 1.0% | Oct 4, 2023 | A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an inse... |
| CVE-2023-5377 | HIGH | 7.1 | 0.3% | Oct 4, 2023 | Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV. |
| CVE-2023-5375 | MEDIUM | 6.1 | 33.6% | Oct 4, 2023 | Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2. |
| CVE-2023-44272 | MEDIUM | 5.4 | 0.4% | Oct 4, 2023 | A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant mes... |
| CVE-2023-5370 | MEDIUM | 5.5 | 0.2% | Oct 4, 2023 | On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no spe... |
| CVE-2023-5369 | HIGH | 7.1 | 0.2% | Oct 4, 2023 | Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input... |
| CVE-2023-5368 | MEDIUM | 6.5 | 0.5% | Oct 4, 2023 | On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional... |
| CVE-2023-30738 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro,... |
| CVE-2023-30737 | MEDIUM | 5.5 | 0.2% | Oct 4, 2023 | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive... |
| CVE-2023-30736 | MEDIUM | 5.4 | 0.2% | Oct 4, 2023 | Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute java... |
| CVE-2023-30735 | LOW | 3.3 | 0.1% | Oct 4, 2023 | Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access b... |
| CVE-2023-30734 | MEDIUM | 5.5 | 0.2% | Oct 4, 2023 | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive... |
| CVE-2023-30733 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attac... |
| CVE-2023-30732 | LOW | 3.3 | 0.2% | Oct 4, 2023 | Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial numbe... |
| CVE-2023-30731 | MEDIUM | 4.6 | 0.2% | Oct 4, 2023 | Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to ins... |
| CVE-2023-30727 | HIGH | 7.5 | 0.4% | Oct 4, 2023 | Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi an... |
| CVE-2023-30692 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch pr... |
| CVE-2023-30690 | HIGH | 7.8 | 0.2% | Oct 4, 2023 | Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileg... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now