2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0462 | CRITICAL | 9.1 | 1.0% | Sep 20, 2023 | An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on t... |
| CVE-2023-0118 | CRITICAL | 9.1 | 1.4% | Sep 20, 2023 | An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates a... |
| CVE-2023-4236 | HIGH | 7.5 | 2.1% | Sep 20, 2023 | A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assert... |
| CVE-2023-43477 | HIGH | 8.8 | 15.7% | Sep 20, 2023 | The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware vers... |
| CVE-2023-3341 | HIGH | 7.5 | 2.6% | Sep 20, 2023 | The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsi... |
| CVE-2023-0829 | CRITICAL | 9 | 0.6% | Sep 20, 2023 | Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a cu... |
| CVE-2023-5042 | HIGH | 7.5 | 0.3% | Sep 20, 2023 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ... |
| CVE-2023-5084 | MEDIUM | 6.1 | 0.4% | Sep 20, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. |
| CVE-2023-4853 | HIGH | 8.1 | 1.2% | Sep 20, 2023 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly whe... |
| CVE-2023-34047 | MEDIUM | 4.3 | 0.4% | Sep 20, 2023 | A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context... |
| CVE-2023-41375 | HIGH | 7.8 | 0.2% | Sep 20, 2023 | Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed ... |
| CVE-2023-41374 | HIGH | 7.8 | 0.2% | Sep 20, 2023 | Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed... |
| CVE-2023-22644 | MEDIUM | 5.5 | 0.5% | Sep 20, 2023 | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a ... |
| CVE-2023-43621 | MEDIUM | 4.7 | 0.3% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users ... |
| CVE-2023-43620 | HIGH | 7.8 | 0.3% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack t... |
| CVE-2023-43619 | HIGH | 7.8 | 0.3% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable c... |
| CVE-2023-43618 | MEDIUM | 5.3 | 0.4% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in clear... |
| CVE-2023-43617 | MEDIUM | 5.3 | 0.6% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge ... |
| CVE-2023-43616 | MEDIUM | 5.5 | 0.4% | Sep 20, 2023 | An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction. |
| CVE-2023-2163 | HIGH | 8.8 | 3.5% | Sep 20, 2023 | Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, res... |
| CVE-2023-26144 | MEDIUM | 5.3 | 1.2% | Sep 20, 2023 | Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insuffici... |
| CVE-2023-5063 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortc... |
| CVE-2023-5062 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in vers... |
| CVE-2023-4088 | HIGH | 7.8 | 0.2% | Sep 20, 2023 | Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products... |
| CVE-2023-31015 | HIGH | 7.8 | 0.2% | Sep 20, 2023 | NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now