2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51672 | HIGH | 7.5 | 0.5% | Apr 11, 2024 | Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a thro... |
| CVE-2023-51142 | HIGH | 7.5 | 0.9% | Apr 11, 2024 | An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information. |
| CVE-2023-52070 | HIGH | 8.4 | 0.3% | Apr 10, 2024 | JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)... |
| CVE-2023-6916 | HIGH | 7.5 | 0.6% | Apr 10, 2024 | Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and pr... |
| CVE-2023-2794 | HIGH | 8.1 | 1.2% | Apr 10, 2024 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_delive... |
| CVE-2023-6236 | HIGH | 7.3 | 0.3% | Apr 10, 2024 | A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to... |
| CVE-2023-7046 | HIGH | 7.5 | 0.4% | Apr 9, 2024 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress... |
| CVE-2023-6999 | HIGH | 8.8 | 1.3% | Apr 9, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in... |
| CVE-2023-6967 | HIGH | 8.8 | 0.8% | Apr 9, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all vers... |
| CVE-2023-49913 | HIGH | 8.8 | 1.9% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49912 | HIGH | 8.8 | 1.8% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49911 | HIGH | 8.8 | 1.8% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49910 | HIGH | 8.8 | 1.8% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49909 | HIGH | 8.8 | 1.8% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49908 | HIGH | 8.8 | 1.8% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49907 | HIGH | 8.8 | 1.8% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49906 | HIGH | 8.8 | 1.9% | Apr 9, 2024 | A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350... |
| CVE-2023-49074 | HIGH | 7.5 | 13.5% | Apr 9, 2024 | A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Poi... |
| CVE-2023-48724 | HIGH | 7.5 | 1.5% | Apr 9, 2024 | A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit A... |
| CVE-2023-45590 | HIGH | 8.8 | 1.5% | Apr 9, 2024 | An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7... |
| CVE-2023-41677 | HIGH | 8.8 | 0.7% | Apr 9, 2024 | A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 th... |
| CVE-2023-6320 | HIGH | 7.2 | 3.9% | Apr 9, 2024 | A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on ... |
| CVE-2023-6319 | HIGH | 7.2 | 6.4% | Apr 9, 2024 | A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanage... |
| CVE-2023-6318 | HIGH | 7.2 | 4.7% | Apr 9, 2024 | A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload ser... |
| CVE-2023-1082 | HIGH | 8.8 | 1.0% | Apr 9, 2024 | An remote attacker with low privileges can perform a command injection which can lead to root access. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now