2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38909 | MEDIUM | 6.5 | 0.8% | Aug 22, 2023 | An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a... |
| CVE-2023-38908 | MEDIUM | 6.5 | 0.5% | Aug 22, 2023 | An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a... |
| CVE-2023-38906 | MEDIUM | 6.5 | 0.5% | Aug 22, 2023 | An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200... |
| CVE-2023-4303 | MEDIUM | 6.1 | 0.4% | Aug 21, 2023 | Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in ... |
| CVE-2023-4302 | MEDIUM | 4.3 | 0.3% | Aug 21, 2023 | A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission t... |
| CVE-2023-4301 | MEDIUM | 5.4 | 0.2% | Aug 21, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to conn... |
| CVE-2023-25915 | HIGH | 8.8 | 0.8% | Aug 21, 2023 | Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system... |
| CVE-2023-25914 | HIGH | 8.8 | 0.7% | Aug 21, 2023 | Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server throu... |
| CVE-2023-25913 | HIGH | 7.5 | 0.5% | Aug 21, 2023 | Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive infor... |
| CVE-2023-38158 | LOW | 3.1 | 1.2% | Aug 21, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2023-36787 | HIGH | 8.8 | 1.8% | Aug 21, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-4459 | MEDIUM | 5.5 | 0.2% | Aug 21, 2023 | A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking s... |
| CVE-2023-4417 | MEDIUM | 6.5 | 0.4% | Aug 21, 2023 | Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier ... |
| CVE-2023-4373 | CRITICAL | 9.8 | 0.7% | Aug 21, 2023 | Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager v... |
| CVE-2023-40352 | HIGH | 7.2 | 0.7% | Aug 21, 2023 | McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by l... |
| CVE-2023-4456 | MEDIUM | 6.5 | 0.5% | Aug 21, 2023 | A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This is... |
| CVE-2023-3954 | MEDIUM | 6.1 | 0.4% | Aug 21, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before... |
| CVE-2023-3936 | MEDIUM | 6.1 | 0.9% | Aug 21, 2023 | The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2023-3667 | MEDIUM | 4.8 | 0.4% | Aug 21, 2023 | The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2023-3604 | HIGH | 7.5 | 0.7% | Aug 21, 2023 | The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a craf... |
| CVE-2023-3366 | MEDIUM | 4.3 | 0.2% | Aug 21, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipme... |
| CVE-2023-39660 | CRITICAL | 9.8 | 1.3% | Aug 21, 2023 | An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a craft... |
| CVE-2023-39106 | HIGH | 8.8 | 1.1% | Aug 21, 2023 | An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via t... |
| CVE-2023-39094 | MEDIUM | 5.4 | 0.4% | Aug 21, 2023 | Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2023-39061 | LOW | 3.5 | 0.3% | Aug 21, 2023 | Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privilege... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now