2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43495 | MEDIUM | 5.4 | 0.9% | Sep 20, 2023 | Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of '... |
| CVE-2023-43494 | MEDIUM | 4.3 | 3.4% | Sep 20, 2023 | Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive buil... |
| CVE-2023-42660 | HIGH | 8.8 | 0.6% | Sep 20, 2023 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ... |
| CVE-2023-42656 | MEDIUM | 6.1 | 0.5% | Sep 20, 2023 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ... |
| CVE-2023-40043 | HIGH | 7.2 | 0.6% | Sep 20, 2023 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ... |
| CVE-2023-5074 | CRITICAL | 9.8 | 67.9% | Sep 20, 2023 | Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Li... |
| CVE-2023-2508 | MEDIUM | 6.5 | 0.2% | Sep 20, 2023 | The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attac... |
| CVE-2023-2262 | CRITICAL | 9.8 | 1.0% | Sep 20, 2023 | A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited... |
| CVE-2023-43636 | HIGH | 8.8 | 0.1% | Sep 20, 2023 | In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in t... |
| CVE-2023-43635 | HIGH | 8.8 | 0.1% | Sep 20, 2023 | Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism... |
| CVE-2023-43630 | HIGH | 8.8 | 0.1% | Sep 20, 2023 | PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit ... |
| CVE-2023-42464 | CRITICAL | 9.8 | 1.8% | Sep 20, 2023 | A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When pa... |
| CVE-2023-43478 | CRITICAL | 9.8 | 17.4% | Sep 20, 2023 | fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated... |
| CVE-2023-43207 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upl... |
| CVE-2023-43206 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_d... |
| CVE-2023-43204 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50.... |
| CVE-2023-43203 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users. |
| CVE-2023-43202 | CRITICAL | 9.8 | 2.3% | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_downl... |
| CVE-2023-43201 | CRITICAL | 9.8 | 0.9% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ex... |
| CVE-2023-43200 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data... |
| CVE-2023-43199 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/logi... |
| CVE-2023-43198 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/h... |
| CVE-2023-43197 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.as... |
| CVE-2023-43196 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp f... |
| CVE-2023-41902 | HIGH | 7.8 | 0.2% | Sep 20, 2023 | An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to esc... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now