2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39780 | HIGH | 8.8 | 32.2% | Sep 11, 2023 | On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply... |
| CVE-2023-39070 | HIGH | 7.8 | 0.3% | Sep 11, 2023 | An issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in... |
| CVE-2023-39068 | HIGH | 7.5 | 0.6% | Sep 11, 2023 | Buffer Overflow vulnerability in NBD80S09S-KLC v.YK_HZXM_NBD80S09S-KLC_V4.03.R11.7601.Nat.OnvifC.20230414.bin and NBD80N... |
| CVE-2023-39063 | HIGH | 7.8 | 0.4% | Sep 11, 2023 | Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server na... |
| CVE-2023-38829 | HIGH | 8.8 | 2.0% | Sep 11, 2023 | An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and tracer... |
| CVE-2023-38743 | HIGH | 7.2 | 11.6% | Sep 11, 2023 | Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine. |
| CVE-2023-31468 | HIGH | 7.8 | 0.8% | Sep 11, 2023 | An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I... |
| CVE-2023-31069 | CRITICAL | 9.8 | 1.9% | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML s... |
| CVE-2023-31068 | CRITICAL | 9.8 | 2.8% | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so... |
| CVE-2023-31067 | CRITICAL | 9.8 | 2.9% | Sep 11, 2023 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so... |
| CVE-2023-41609 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim us... |
| CVE-2023-41593 | MEDIUM | 5.4 | 0.8% | Sep 11, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow ... |
| CVE-2023-39067 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a cra... |
| CVE-2023-4881 | — | — | — | Sep 11, 2023 | Rejected reason: CVE-2023-4881 was wrongly assigned to a bug that was deemed to be a non-security issue by the Linux ker... |
| CVE-2023-30058 | CRITICAL | 9.8 | 0.8% | Sep 11, 2023 | novel-plus 3.6.2 is vulnerable to SQL Injection. |
| CVE-2023-41000 | MEDIUM | 5.5 | 0.3% | Sep 11, 2023 | GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.... |
| CVE-2023-36140 | CRITICAL | 9.8 | 0.4% | Sep 11, 2023 | In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain acce... |
| CVE-2023-27470 | HIGH | 7 | 0.5% | Sep 11, 2023 | BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a ps... |
| CVE-2023-4630 | MEDIUM | 4.3 | 0.4% | Sep 11, 2023 | An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting fr... |
| CVE-2023-40786 | MEDIUM | 5.4 | 0.3% | Sep 11, 2023 | HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen. |
| CVE-2023-36980 | MEDIUM | 5.3 | 0.4% | Sep 11, 2023 | An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casin... |
| CVE-2023-36161 | HIGH | 7.5 | 0.5% | Sep 11, 2023 | An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of ... |
| CVE-2023-3612 | HIGH | 8.8 | 0.4% | Sep 11, 2023 | Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an U... |
| CVE-2023-4585 | HIGH | 8.8 | 0.7% | Sep 11, 2023 | Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence ... |
| CVE-2023-4584 | HIGH | 8.8 | 0.7% | Sep 11, 2023 | Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 11... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now