2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31808 | HIGH | 7.2 | 0.5% | Sep 19, 2023 | Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative p... |
| CVE-2023-4092 | CRITICAL | 9.8 | 0.6% | Sep 19, 2023 | SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow... |
| CVE-2023-41834 | MEDIUM | 6.1 | 1.6% | Sep 19, 2023 | Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allo... |
| CVE-2023-23957 | MEDIUM | 5.4 | 0.3% | Sep 19, 2023 | An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4 |
| CVE-2023-32649 | HIGH | 7.5 | 0.5% | Sep 19, 2023 | A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain... |
| CVE-2023-2567 | HIGH | 8.8 | 0.5% | Sep 19, 2023 | A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in ce... |
| CVE-2023-29245 | HIGH | 7.4 | 0.5% | Sep 19, 2023 | A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields us... |
| CVE-2023-32186 | HIGH | 7.5 | 0.6% | Sep 19, 2023 | A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s s... |
| CVE-2023-32184 | HIGH | 7.8 | 0.3% | Sep 19, 2023 | A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute... |
| CVE-2023-0773 | CRITICAL | 9.8 | 1.2% | Sep 19, 2023 | The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based manageme... |
| CVE-2023-41387 | CRITICAL | 9.1 | 0.7% | Sep 19, 2023 | A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session toke... |
| CVE-2023-5009 | CRITICAL | 9.8 | 8.3% | Sep 19, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions startin... |
| CVE-2023-5054 | MEDIUM | 5.3 | 0.5% | Sep 19, 2023 | The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versi... |
| CVE-2023-26143 | CRITICAL | 9.1 | 0.9% | Sep 19, 2023 | Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. Th... |
| CVE-2023-42399 | MEDIUM | 6.1 | 0.5% | Sep 19, 2023 | Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensiti... |
| CVE-2023-5060 | MEDIUM | 6.1 | 0.6% | Sep 19, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1. |
| CVE-2023-41599 | MEDIUM | 5.3 | 11.2% | Sep 19, 2023 | An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traver... |
| CVE-2023-40788 | MEDIUM | 5.3 | 0.6% | Sep 19, 2023 | SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway res... |
| CVE-2023-42454 | CRITICAL | 9.1 | 0.6% | Sep 18, 2023 | SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed ... |
| CVE-2023-42446 | MEDIUM | 6.5 | 0.5% | Sep 18, 2023 | Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and pri... |
| CVE-2023-41443 | HIGH | 7.2 | 1.1% | Sep 18, 2023 | SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted scrip... |
| CVE-2023-39056 | MEDIUM | 6.5 | 0.4% | Sep 18, 2023 | An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted message... |
| CVE-2023-39049 | MEDIUM | 6.5 | 0.4% | Sep 18, 2023 | An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted mes... |
| CVE-2023-39046 | MEDIUM | 6.5 | 0.4% | Sep 18, 2023 | An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send craf... |
| CVE-2023-37611 | MEDIUM | 5.4 | 0.6% | Sep 18, 2023 | Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary c... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now