2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38976 | HIGH | 7.5 | 1.7% | Aug 21, 2023 | An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLReques... |
| CVE-2023-38961 | CRITICAL | 9.8 | 1.2% | Aug 21, 2023 | Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary c... |
| CVE-2023-38836 | HIGH | 8.8 | 73.0% | Aug 21, 2023 | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t... |
| CVE-2023-38035 | CRITICAL | 9.8 | 99.9% | Aug 21, 2023 | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an ... |
| CVE-2023-32002 | CRITICAL | 9.8 | 1.4% | Aug 21, 2023 | The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition fo... |
| CVE-2023-31447 | CRITICAL | 9.8 | 0.9% | Aug 21, 2023 | user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers t... |
| CVE-2023-40735 | HIGH | 7.5 | 0.6% | Aug 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFL... |
| CVE-2023-38899 | HIGH | 7.8 | 0.4% | Aug 21, 2023 | SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_fi... |
| CVE-2023-3481 | MEDIUM | 6.1 | 0.1% | Aug 21, 2023 | Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XS... |
| CVE-2023-4455 | MEDIUM | 6.5 | 0.3% | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. |
| CVE-2023-4454 | MEDIUM | 5.7 | 0.2% | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. |
| CVE-2023-4453 | MEDIUM | 5.4 | 0.5% | Aug 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8. |
| CVE-2023-40068 | MEDIUM | 5.4 | 1.5% | Aug 21, 2023 | Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro vers... |
| CVE-2023-39939 | CRITICAL | 9.1 | 0.7% | Aug 21, 2023 | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.... |
| CVE-2023-39543 | MEDIUM | 6.1 | 0.5% | Aug 21, 2023 | Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior ... |
| CVE-2023-4450 | CRITICAL | 9.8 | 11.4% | Aug 21, 2023 | A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulner... |
| CVE-2023-39751 | CRITICAL | 9.8 | 7.8% | Aug 21, 2023 | TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm. |
| CVE-2023-39750 | CRITICAL | 9.8 | 12.8% | Aug 21, 2023 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vul... |
| CVE-2023-39749 | CRITICAL | 9.8 | 1.0% | Aug 21, 2023 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is... |
| CVE-2023-39748 | HIGH | 7.5 | 0.6% | Aug 21, 2023 | An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service ... |
| CVE-2023-39747 | CRITICAL | 9.8 | 7.8% | Aug 21, 2023 | TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSe... |
| CVE-2023-39745 | HIGH | 7.5 | 0.6% | Aug 21, 2023 | TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via th... |
| CVE-2023-4449 | HIGH | 8.8 | 0.7% | Aug 21, 2023 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been classified... |
| CVE-2023-4448 | CRITICAL | 9.8 | 0.5% | Aug 21, 2023 | A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown proces... |
| CVE-2023-4447 | CRITICAL | 9.8 | 0.5% | Aug 21, 2023 | A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknow... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now