2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41775 | MEDIUM | 5.5 | 0.2% | Sep 8, 2023 | Improper access control vulnerability in 'direct' Desktop App for macOS ver 2.6.0 and earlier allows a local attacker to... |
| CVE-2023-34041 | MEDIUM | 5.3 | 0.4% | Sep 8, 2023 | Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthent... |
| CVE-2023-32470 | MEDIUM | 5.5 | 0.2% | Sep 8, 2023 | Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulner... |
| CVE-2023-41615 | CRITICAL | 9.8 | 0.8% | Sep 8, 2023 | Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page vi... |
| CVE-2023-41594 | HIGH | 7.5 | 0.8% | Sep 8, 2023 | Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilit... |
| CVE-2023-40953 | HIGH | 8.8 | 0.2% | Sep 8, 2023 | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2023-40353 | LOW | 3.3 | 0.2% | Sep 8, 2023 | An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the e... |
| CVE-2023-39620 | HIGH | 7.5 | 0.7% | Sep 8, 2023 | An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitiv... |
| CVE-2023-37759 | CRITICAL | 9.8 | 3.6% | Sep 8, 2023 | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat... |
| CVE-2023-37377 | HIGH | 7.5 | 0.3% | Sep 8, 2023 | An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100, ... |
| CVE-2023-37368 | HIGH | 7.5 | 0.5% | Sep 8, 2023 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos Mobile Processor, Au... |
| CVE-2023-37367 | MEDIUM | 5.3 | 0.4% | Sep 8, 2023 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Ex... |
| CVE-2023-40271 | HIGH | 7.5 | 0.3% | Sep 8, 2023 | In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell P... |
| CVE-2023-36184 | HIGH | 7.5 | 0.9% | Sep 8, 2023 | CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json. |
| CVE-2023-40584 | MEDIUM | 6.5 | 1.2% | Sep 7, 2023 | Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug wher... |
| CVE-2023-40029 | CRITICAL | 9.6 | 1.0% | Sep 7, 2023 | Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively us... |
| CVE-2023-41646 | MEDIUM | 5.3 | 0.4% | Sep 7, 2023 | Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the ... |
| CVE-2023-41161 | MEDIUM | 5.4 | 0.4% | Sep 7, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary w... |
| CVE-2023-30908 | CRITICAL | 9.8 | 1.2% | Sep 7, 2023 | A remote authentication bypass issue exists in a OneView API. |
| CVE-2023-41316 | MEDIUM | 5.4 | 0.4% | Sep 7, 2023 | Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails wi... |
| CVE-2023-20194 | MEDIUM | 4.9 | 0.5% | Sep 7, 2023 | A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the... |
| CVE-2023-20193 | MEDIUM | 6.7 | 0.2% | Sep 7, 2023 | A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, ... |
| CVE-2023-37798 | MEDIUM | 5.4 | 0.5% | Sep 7, 2023 | A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.... |
| CVE-2023-4685 | HIGH | 7.8 | 0.2% | Sep 7, 2023 | Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffe... |
| CVE-2023-4528 | HIGH | 7.2 | 27.1% | Sep 7, 2023 | Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now