2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44048 | MEDIUM | 5.4 | 0.4% | Sep 27, 2023 | Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category. |
| CVE-2023-44047 | HIGH | 7.2 | 0.7% | Sep 27, 2023 | Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection. |
| CVE-2023-4523 | MEDIUM | 6.1 | 0.3% | Sep 27, 2023 | Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which co... |
| CVE-2023-43652 | CRITICAL | 9.1 | 0.7% | Sep 27, 2023 | JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API wi... |
| CVE-2023-43650 | HIGH | 7.4 | 0.5% | Sep 27, 2023 | JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-fo... |
| CVE-2023-33972 | HIGH | 8.8 | 0.5% | Sep 27, 2023 | Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who ar... |
| CVE-2023-5184 | HIGH | 8.8 | 0.4% | Sep 27, 2023 | Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the... |
| CVE-2023-42822 | MEDIUM | 6.5 | 0.6% | Sep 27, 2023 | xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked... |
| CVE-2023-20268 | MEDIUM | 4.7 | 0.2% | Sep 27, 2023 | A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticate... |
| CVE-2023-20262 | HIGH | 7.5 | 0.7% | Sep 27, 2023 | A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to c... |
| CVE-2023-20254 | HIGH | 8.8 | 0.6% | Sep 27, 2023 | A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow a... |
| CVE-2023-20253 | MEDIUM | 5.5 | 0.2% | Sep 27, 2023 | A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenti... |
| CVE-2023-20252 | CRITICAL | 9.8 | 1.1% | Sep 27, 2023 | A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could al... |
| CVE-2023-20251 | MEDIUM | 5.3 | 0.2% | Sep 27, 2023 | A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticat... |
| CVE-2023-20231 | HIGH | 8.8 | 0.7% | Sep 27, 2023 | A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injec... |
| CVE-2023-20227 | HIGH | 7.5 | 0.7% | Sep 27, 2023 | A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated... |
| CVE-2023-20226 | HIGH | 7.5 | 0.7% | Sep 27, 2023 | A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software ... |
| CVE-2023-20223 | HIGH | 8.2 | 0.5% | Sep 27, 2023 | A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a reposit... |
| CVE-2023-20202 | MEDIUM | 6.5 | 0.2% | Sep 27, 2023 | A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers coul... |
| CVE-2023-20187 | HIGH | 7.5 | 0.7% | Sep 27, 2023 | A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Ser... |
| CVE-2023-20186 | CRITICAL | 9.1 | 0.6% | Sep 27, 2023 | A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS X... |
| CVE-2023-20179 | MEDIUM | 5.4 | 0.4% | Sep 27, 2023 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c... |
| CVE-2023-20176 | HIGH | 8.6 | 0.7% | Sep 27, 2023 | A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote a... |
| CVE-2023-20109 | MEDIUM | 6.6 | 2.3% | Sep 27, 2023 | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Soft... |
| CVE-2023-20034 | HIGH | 7.5 | 0.6% | Sep 27, 2023 | Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated,... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now