2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41031 | HIGH | 8.8 | 1.7% | Sep 22, 2023 | Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authentic... |
| CVE-2023-41029 | HIGH | 8.8 | 2.2% | Sep 22, 2023 | Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1... |
| CVE-2023-41027 | HIGH | 8.8 | 0.8% | Sep 22, 2023 | Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 an... |
| CVE-2023-42811 | MEDIUM | 5.5 | 0.3% | Sep 22, 2023 | aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES... |
| CVE-2023-42798 | CRITICAL | 9.1 | 0.3% | Sep 22, 2023 | AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1... |
| CVE-2023-43144 | CRITICAL | 9.8 | 0.9% | Sep 22, 2023 | Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php. |
| CVE-2023-23766 | MEDIUM | 6.5 | 0.6% | Sep 22, 2023 | An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa... |
| CVE-2023-5002 | HIGH | 8.8 | 1.5% | Sep 22, 2023 | A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to ext... |
| CVE-2023-34319 | HIGH | 7.8 | 0.3% | Sep 22, 2023 | The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that... |
| CVE-2023-4774 | MEDIUM | 5.4 | 0.5% | Sep 22, 2023 | The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik... |
| CVE-2023-4716 | MEDIUM | 5.4 | 0.5% | Sep 22, 2023 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor... |
| CVE-2023-43784 | HIGH | 7.5 | 0.5% | Sep 22, 2023 | Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE... |
| CVE-2023-43783 | HIGH | 7.5 | 0.6% | Sep 22, 2023 | Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if... |
| CVE-2023-43782 | MEDIUM | 5.5 | 0.3% | Sep 22, 2023 | Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if ... |
| CVE-2023-43771 | MEDIUM | 5.5 | 0.2% | Sep 22, 2023 | In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program. |
| CVE-2023-43770 | MEDIUM | 6.1 | 56.9% | Sep 22, 2023 | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft... |
| CVE-2023-43090 | MEDIUM | 5.5 | 0.3% | Sep 22, 2023 | A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows... |
| CVE-2023-43767 | HIGH | 7.5 | 0.5% | Sep 22, 2023 | Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Clien... |
| CVE-2023-43766 | HIGH | 7.8 | 0.2% | Sep 22, 2023 | Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure... |
| CVE-2023-43765 | HIGH | 7.5 | 0.5% | Sep 22, 2023 | Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, ... |
| CVE-2023-43764 | — | — | — | Sep 22, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-43762. Reason: This candidate is a duplicate of ... |
| CVE-2023-43763 | MEDIUM | 6.1 | 0.3% | Sep 22, 2023 | Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manag... |
| CVE-2023-43762 | CRITICAL | 9.8 | 1.1% | Sep 22, 2023 | Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithS... |
| CVE-2023-43761 | HIGH | 7.5 | 0.5% | Sep 22, 2023 | Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSec... |
| CVE-2023-43760 | HIGH | 7.5 | 0.5% | Sep 22, 2023 | Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now