2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42443 | HIGH | 8.1 | 0.7% | Sep 18, 2023 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under ce... |
| CVE-2023-42441 | MEDIUM | 5.3 | 0.4% | Sep 18, 2023 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Starting in version 0.2.9 and prior ... |
| CVE-2023-39452 | HIGH | 7.5 | 0.5% | Sep 18, 2023 | The web application that owns the device clearly stores the credentials within the user management sectio... |
| CVE-2023-39446 | HIGH | 8.8 | 0.2% | Sep 18, 2023 | Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the ... |
| CVE-2023-39058 | MEDIUM | 6.5 | 0.4% | Sep 18, 2023 | An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted m... |
| CVE-2023-39043 | MEDIUM | 6.5 | 0.5% | Sep 18, 2023 | An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and sen... |
| CVE-2023-39040 | MEDIUM | 6.5 | 0.4% | Sep 18, 2023 | An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted mes... |
| CVE-2023-39039 | MEDIUM | 6.5 | 0.4% | Sep 18, 2023 | An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send craf... |
| CVE-2023-38582 | MEDIUM | 5.4 | 0.4% | Sep 18, 2023 | Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote a... |
| CVE-2023-38255 | MEDIUM | 6.1 | 0.3% | Sep 18, 2023 | A potential attacker with or without (cookie theft) access to the device would be able to include malic... |
| CVE-2023-41965 | HIGH | 7.5 | 0.5% | Sep 18, 2023 | Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack ... |
| CVE-2023-41084 | CRITICAL | 9.8 | 0.6% | Sep 18, 2023 | Session management within the web application is incorrect and allows attackers to steal session cookies to p... |
| CVE-2023-40221 | HIGH | 8.8 | 0.5% | Sep 18, 2023 | The absence of filters when loading some sections in the web application of the vulnerable device allows po... |
| CVE-2023-33831 | CRITICAL | 9.8 | 13.7% | Sep 18, 2023 | A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute... |
| CVE-2023-41030 | CRITICAL | 9.8 | 0.6% | Sep 18, 2023 | Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to t... |
| CVE-2023-4806 | MEDIUM | 5.9 | 1.4% | Sep 18, 2023 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has... |
| CVE-2023-4527 | MEDIUM | 6.5 | 1.5% | Sep 18, 2023 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is c... |
| CVE-2023-42328 | HIGH | 8.8 | 1.2% | Sep 18, 2023 | An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and ex... |
| CVE-2023-42320 | CRITICAL | 9.8 | 0.9% | Sep 18, 2023 | Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a ... |
| CVE-2023-41595 | HIGH | 7.5 | 0.5% | Sep 18, 2023 | An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. |
| CVE-2023-42387 | HIGH | 7.5 | 0.7% | Sep 18, 2023 | An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via g... |
| CVE-2023-42371 | MEDIUM | 5.4 | 0.5% | Sep 18, 2023 | Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execut... |
| CVE-2023-34195 | HIGH | 7.8 | 0.2% | Sep 18, 2023 | An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The imple... |
| CVE-2023-32187 | HIGH | 7.5 | 0.6% | Sep 18, 2023 | An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s se... |
| CVE-2023-42359 | CRITICAL | 9.8 | 0.7% | Sep 18, 2023 | SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate p... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now