2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26151 | HIGH | 7.5 | 1.0% | Oct 3, 2023 | Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a... |
| CVE-2023-26150 | HIGH | 7.5 | 0.5% | Oct 3, 2023 | Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to acce... |
| CVE-2023-5345 | HIGH | 7.8 | 0.5% | Oct 3, 2023 | A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege... |
| CVE-2023-5334 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsi... |
| CVE-2023-3967 | HIGH | 7.5 | 0.5% | Oct 3, 2023 | Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows... |
| CVE-2023-3440 | HIGH | 7.8 | 0.2% | Oct 3, 2023 | Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.Th... |
| CVE-2023-3335 | MEDIUM | 5.5 | 0.2% | Oct 3, 2023 | Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local... |
| CVE-2023-43627 | MEDIUM | 5.7 | 0.3% | Oct 3, 2023 | Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier... |
| CVE-2023-42771 | HIGH | 8.8 | 0.3% | Oct 3, 2023 | Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and ... |
| CVE-2023-41086 | HIGH | 8.8 | 0.2% | Oct 3, 2023 | Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user vi... |
| CVE-2023-39429 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to i... |
| CVE-2023-39222 | HIGH | 8.8 | 1.3% | Oct 3, 2023 | OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to e... |
| CVE-2023-36628 | HIGH | 8.8 | 0.5% | Oct 3, 2023 | A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access ... |
| CVE-2023-32572 | MEDIUM | 4.9 | 0.4% | Oct 3, 2023 | A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention l... |
| CVE-2023-28373 | LOW | 2.7 | 0.4% | Oct 3, 2023 | A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the ... |
| CVE-2023-43980 | CRITICAL | 9.8 | 0.5% | Oct 2, 2023 | Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component di... |
| CVE-2023-36627 | LOW | 2.7 | 0.5% | Oct 2, 2023 | A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is confi... |
| CVE-2023-31042 | MEDIUM | 4.3 | 0.5% | Oct 2, 2023 | A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can i... |
| CVE-2023-28372 | LOW | 2.7 | 0.5% | Oct 2, 2023 | A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention per... |
| CVE-2023-44012 | MEDIUM | 6.1 | 1.3% | Oct 2, 2023 | Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the he... |
| CVE-2023-44011 | CRITICAL | 9.8 | 1.4% | Oct 2, 2023 | An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.m... |
| CVE-2023-43893 | CRITICAL | 9.8 | 1.9% | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the W... |
| CVE-2023-43892 | CRITICAL | 9.8 | 1.9% | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the... |
| CVE-2023-43891 | CRITICAL | 9.8 | 1.9% | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password... |
| CVE-2023-44009 | CRITICAL | 9.8 | 1.4% | Oct 2, 2023 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Manage... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now