2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46158 | CRITICAL | 9.8 | 0.5% | Oct 25, 2023 | IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to i... |
| CVE-2023-46010 | CRITICAL | 9.8 | 1.2% | Oct 25, 2023 | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. |
| CVE-2023-45554 | CRITICAL | 9.8 | 1.5% | Oct 25, 2023 | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the i... |
| CVE-2023-44794 | CRITICAL | 9.8 | 1.0% | Oct 25, 2023 | An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payl... |
| CVE-2023-43795 | CRITICAL | 9.8 | 67.7% | Oct 25, 2023 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC... |
| CVE-2023-42494 | CRITICAL | 9.8 | 0.7% | Oct 25, 2023 | EisBaer Scada - CWE-749: Exposed Dangerous Method or Function |
| CVE-2023-42493 | CRITICAL | 9.8 | 0.4% | Oct 25, 2023 | EisBaer Scada - CWE-256: Plaintext Storage of a Password |
| CVE-2023-42492 | CRITICAL | 9.8 | 0.4% | Oct 25, 2023 | EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key |
| CVE-2023-42491 | CRITICAL | 9.8 | 0.6% | Oct 25, 2023 | EisBaer Scada - CWE-285: Improper Authorization |
| CVE-2023-42489 | CRITICAL | 9.8 | 0.7% | Oct 25, 2023 | EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource |
| CVE-2023-39930 | CRITICAL | 9.8 | 0.7% | Oct 25, 2023 | A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authe... |
| CVE-2023-37908 | CRITICAL | 9.6 | 1.1% | Oct 25, 2023 | XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cle... |
| CVE-2023-37283 | CRITICAL | 9.8 | 0.7% | Oct 25, 2023 | Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Iden... |
| CVE-2023-34048 | CRITICAL | 9.8 | 99.4% | Oct 25, 2023 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious a... |
| CVE-2023-31581 | CRITICAL | 9.8 | 0.8% | Oct 25, 2023 | Dromara Sureness before v1.0.8 was discovered to use a hardcoded key. |
| CVE-2023-30912 | CRITICAL | 9.8 | 1.2% | Oct 25, 2023 | A remote code execution issue exists in HPE OneView. |
| CVE-2023-27262 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier... |
| CVE-2023-27260 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier... |
| CVE-2023-27255 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier ... |
| CVE-2023-27254 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allo... |
| CVE-2023-26584 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetStudentInconsistencies method in IDAttend’s IDWeb application 3.1.052 and ea... |
| CVE-2023-26583 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetCurrentPeriod method in IDAttend’s IDWeb application 3.1.052 and earlier allo... |
| CVE-2023-26582 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier al... |
| CVE-2023-26581 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetVisitors method in IDAttend’s IDWeb application 3.1.052 and earlier allows extr... |
| CVE-2023-26573 | CRITICAL | 9.1 | 0.7% | Oct 25, 2023 | Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now