2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20036 | CRITICAL | 9.9 | 12.7% | Nov 15, 2024 | A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands w... |
| CVE-2023-52268 | CRITICAL | 9.1 | 0.6% | Nov 12, 2024 | The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user... |
| CVE-2023-27195 | CRITICAL | 9.8 | 1.0% | Nov 8, 2024 | Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve th... |
| CVE-2023-52044 | CRITICAL | 9.8 | 0.8% | Oct 31, 2024 | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files wi... |
| CVE-2023-26785 | CRITICAL | 9.8 | 2.1% | Oct 17, 2024 | MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File... |
| CVE-2023-32191 | CRITICAL | 9.9 | 0.6% | Oct 16, 2024 | When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-s... |
| CVE-2023-32188 | CRITICAL | 9.4 | 0.5% | Oct 16, 2024 | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a ... |
| CVE-2023-48082 | CRITICAL | 9.1 | 1.5% | Oct 14, 2024 | Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers... |
| CVE-2023-25581 | CRITICAL | 9.2 | 1.9% | Oct 10, 2024 | pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulner... |
| CVE-2023-46586 | CRITICAL | 9.1 | 0.6% | Oct 9, 2024 | cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strn... |
| CVE-2023-52952 | CRITICAL | 9.3 | 0.2% | Oct 8, 2024 | A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiM... |
| CVE-2023-26770 | CRITICAL | 9.8 | 0.7% | Oct 4, 2024 | TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can chan... |
| CVE-2023-3441 | CRITICAL | 9.1 | 0.5% | Oct 1, 2024 | An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not s... |
| CVE-2023-26689 | CRITICAL | 9.8 | 0.6% | Sep 25, 2024 | An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted ... |
| CVE-2023-26686 | CRITICAL | 9.8 | 0.7% | Sep 25, 2024 | File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image uplo... |
| CVE-2023-27584 | CRITICAL | 9.8 | 29.8% | Sep 19, 2024 | Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native ... |
| CVE-2023-37234 | CRITICAL | 9.8 | 0.4% | Sep 10, 2024 | Loftware Spectrum through 4.6 has unprotected JMX Registry. |
| CVE-2023-36103 | CRITICAL | 9.8 | 1.4% | Sep 10, 2024 | Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run... |
| CVE-2023-37231 | CRITICAL | 9.8 | 0.5% | Sep 10, 2024 | Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password. |
| CVE-2023-37227 | CRITICAL | 9.8 | 0.6% | Sep 10, 2024 | Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. |
| CVE-2023-37226 | CRITICAL | 9.8 | 0.6% | Sep 10, 2024 | Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. |
| CVE-2023-26324 | CRITICAL | 9.8 | 0.6% | Aug 28, 2024 | A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the veri... |
| CVE-2023-26323 | CRITICAL | 9.8 | 0.6% | Aug 28, 2024 | A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configurat... |
| CVE-2023-26322 | CRITICAL | 9.8 | 0.7% | Aug 28, 2024 | A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the veri... |
| CVE-2023-26321 | CRITICAL | 9.8 | 0.5% | Aug 28, 2024 | A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnera... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now