2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45209 | HIGH | 7.5 | 1.4% | Apr 17, 2024 | An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplin... |
| CVE-2023-43491 | HIGH | 7.5 | 1.5% | Apr 17, 2024 | An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Sma... |
| CVE-2023-39367 | HIGH | 7.2 | 37.7% | Apr 17, 2024 | An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 ... |
| CVE-2023-51500 | HIGH | 7.7 | 0.5% | Apr 17, 2024 | Missing Authorization vulnerability in Undsgn Uncode Core.This issue affects Uncode Core: from n/a through 2.8.8. |
| CVE-2023-51418 | HIGH | 7.7 | 0.5% | Apr 17, 2024 | Missing Authorization vulnerability in Joris van Montfort JVM rich text icons.This issue affects JVM rich text icons: fr... |
| CVE-2023-52642 | HIGH | 7.8 | 0.2% | Apr 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: rc: bpf attach/detach requires write permiss... |
| CVE-2023-44227 | HIGH | 7.5 | 0.6% | Apr 17, 2024 | Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a th... |
| CVE-2023-36505 | HIGH | 7.2 | 0.6% | Apr 17, 2024 | Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contac... |
| CVE-2023-51391 | HIGH | 7.5 | 0.8% | Apr 16, 2024 | A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially al... |
| CVE-2023-50872 | HIGH | 7.5 | 0.4% | Apr 16, 2024 | The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses... |
| CVE-2023-33806 | HIGH | 7.8 | 0.2% | Apr 15, 2024 | Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to exe... |
| CVE-2023-4857 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to exe... |
| CVE-2023-4856 | HIGH | 8.8 | 0.7% | Apr 15, 2024 | A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbi... |
| CVE-2023-4855 | HIGH | 7.2 | 1.1% | Apr 15, 2024 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat... |
| CVE-2023-48709 | HIGH | 8 | 1.0% | Apr 15, 2024 | iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' ... |
| CVE-2023-51515 | HIGH | 8.8 | 0.6% | Apr 12, 2024 | Missing Authorization vulnerability in Undsgn Uncode Core allows Privilege Escalation.This issue affects Uncode Core: fr... |
| CVE-2023-49528 | HIGH | 8 | 0.4% | Apr 12, 2024 | Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code an... |
| CVE-2023-44857 | HIGH | 8.1 | 0.9% | Apr 12, 2024 | An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to ... |
| CVE-2023-44852 | HIGH | 8.2 | 0.6% | Apr 12, 2024 | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra... |
| CVE-2023-5394 | HIGH | 7.4 | 0.7% | Apr 11, 2024 | Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overfl... |
| CVE-2023-5393 | HIGH | 7.4 | 0.7% | Apr 11, 2024 | Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in po... |
| CVE-2023-5392 | HIGH | 7.5 | 0.5% | Apr 11, 2024 | C300 information leak due to an analysis feature which allows extracting more memory over the network than required by t... |
| CVE-2023-50949 | HIGH | 8.1 | 0.3% | Apr 11, 2024 | IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validat... |
| CVE-2023-29483 | HIGH | 7 | 1.9% | Apr 11, 2024 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution... |
| CVE-2023-6811 | HIGH | 7.2 | 0.4% | Apr 11, 2024 | The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now