2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40931 | MEDIUM | 6.5 | 13.5% | Sep 19, 2023 | A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers... |
| CVE-2023-4376 | MEDIUM | 4.8 | 0.4% | Sep 19, 2023 | The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and e... |
| CVE-2023-2995 | MEDIUM | 4.8 | 0.4% | Sep 19, 2023 | The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privi... |
| CVE-2023-43566 | MEDIUM | 5.4 | 0.9% | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration |
| CVE-2023-42793 | CRITICAL | 9.8 | 100.0% | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible |
| CVE-2023-22513 | HIGH | 8.8 | 14.3% | Sep 19, 2023 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center an... |
| CVE-2023-42452 | MEDIUM | 5.4 | 0.4% | Sep 19, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versi... |
| CVE-2023-42451 | HIGH | 7.5 | 0.6% | Sep 19, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and... |
| CVE-2023-42450 | HIGH | 7.5 | 0.4% | Sep 19, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to... |
| CVE-2023-38356 | HIGH | 8.1 | 0.6% | Sep 19, 2023 | MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code... |
| CVE-2023-38355 | HIGH | 8.1 | 0.6% | Sep 19, 2023 | MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code executio... |
| CVE-2023-38354 | HIGH | 8.1 | 0.6% | Sep 19, 2023 | MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code... |
| CVE-2023-38353 | MEDIUM | 5.9 | 0.4% | Sep 19, 2023 | MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to... |
| CVE-2023-38352 | HIGH | 8.1 | 0.6% | Sep 19, 2023 | MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execut... |
| CVE-2023-38351 | HIGH | 8.1 | 0.6% | Sep 19, 2023 | MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code ... |
| CVE-2023-32182 | HIGH | 7.8 | 0.3% | Sep 19, 2023 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 ... |
| CVE-2023-42447 | HIGH | 7.5 | 0.5% | Sep 19, 2023 | blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turne... |
| CVE-2023-42444 | HIGH | 7.5 | 0.7% | Sep 19, 2023 | phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.... |
| CVE-2023-41890 | HIGH | 7.5 | 0.6% | Sep 19, 2023 | Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provi... |
| CVE-2023-3892 | HIGH | 7.4 | 0.2% | Sep 19, 2023 | Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modul... |
| CVE-2023-4096 | HIGH | 8.2 | 0.3% | Sep 19, 2023 | Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow ... |
| CVE-2023-4095 | MEDIUM | 5.3 | 0.4% | Sep 19, 2023 | User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an a... |
| CVE-2023-4094 | HIGH | 8.2 | 0.4% | Sep 19, 2023 | ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests... |
| CVE-2023-4093 | MEDIUM | 6.1 | 0.3% | Sep 19, 2023 | Reflected and persistent XSS vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerabil... |
| CVE-2023-41179 | HIGH | 7.2 | 4.7% | Sep 19, 2023 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now