2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26572 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetExcursionList method in IDAttend’s IDWeb application 3.1.052 and earlier allows ... |
| CVE-2023-26569 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and ea... |
| CVE-2023-26568 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier ... |
| CVE-2023-37635 | CRITICAL | 9.8 | 1.2% | Oct 23, 2023 | UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to ga... |
| CVE-2023-27152 | CRITICAL | 9.8 | 0.9% | Oct 23, 2023 | DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack ... |
| CVE-2023-28805 | CRITICAL | 9.8 | 0.3% | Oct 23, 2023 | An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue ... |
| CVE-2023-5700 | CRITICAL | 9.8 | 0.6% | Oct 23, 2023 | A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affec... |
| CVE-2023-46322 | CRITICAL | 9.8 | 0.7% | Oct 23, 2023 | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial char... |
| CVE-2023-46321 | CRITICAL | 9.8 | 0.7% | Oct 23, 2023 | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell meta... |
| CVE-2023-5693 | CRITICAL | 9.8 | 0.6% | Oct 22, 2023 | A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some u... |
| CVE-2023-46301 | CRITICAL | 9.8 | 1.2% | Oct 22, 2023 | iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences relate... |
| CVE-2023-46300 | CRITICAL | 9.8 | 1.2% | Oct 22, 2023 | iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences relate... |
| CVE-2023-5684 | CRITICAL | 9.8 | 78.4% | Oct 21, 2023 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Aff... |
| CVE-2023-5683 | CRITICAL | 9.8 | 18.0% | Oct 21, 2023 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue... |
| CVE-2023-45666 | CRITICAL | 9.8 | 1.0% | Oct 21, 2023 | stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t g... |
| CVE-2023-5682 | CRITICAL | 9.8 | 0.7% | Oct 20, 2023 | A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of ... |
| CVE-2023-37824 | CRITICAL | 9.8 | 0.5% | Oct 20, 2023 | Sitolog sitologapplicationconnect v7.8.a and before was discovered to contain a SQL injection vulnerability via the comp... |
| CVE-2023-5533 | CRITICAL | 9.8 | 0.5% | Oct 20, 2023 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks o... |
| CVE-2023-5576 | CRITICAL | 9.3 | 0.8% | Oct 20, 2023 | The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in version... |
| CVE-2023-4488 | CRITICAL | 9.8 | 1.0% | Oct 20, 2023 | The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via... |
| CVE-2023-4402 | CRITICAL | 9.8 | 1.3% | Oct 20, 2023 | The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 ... |
| CVE-2023-39680 | CRITICAL | 9.8 | 0.6% | Oct 20, 2023 | Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute ar... |
| CVE-2023-34051 | CRITICAL | 9.8 | 44.7% | Oct 20, 2023 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can... |
| CVE-2023-41897 | CRITICAL | 9.6 | 0.9% | Oct 19, 2023 | Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, includin... |
| CVE-2023-41896 | CRITICAL | 9 | 0.3% | Oct 19, 2023 | Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure5... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now