2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4052 | MEDIUM | 6.5 | 0.6% | Aug 1, 2023 | The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that d... |
| CVE-2023-4051 | HIGH | 7.5 | 0.5% | Aug 1, 2023 | A website could have obscured the full screen notification by using the file open dialog. This could have led to user co... |
| CVE-2023-4050 | HIGH | 7.5 | 13.7% | Aug 1, 2023 | In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a pote... |
| CVE-2023-4049 | MEDIUM | 5.9 | 0.6% | Aug 1, 2023 | Race conditions in reference counting code were found through code inspection. These could have resulted in potentially ... |
| CVE-2023-4048 | HIGH | 7.5 | 0.8% | Aug 1, 2023 | An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. ... |
| CVE-2023-4047 | HIGH | 8.8 | 0.6% | Aug 1, 2023 | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting... |
| CVE-2023-4046 | MEDIUM | 5.3 | 1.0% | Aug 1, 2023 | In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in i... |
| CVE-2023-4045 | MEDIUM | 5.3 | 0.5% | Aug 1, 2023 | Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from anot... |
| CVE-2023-38357 | MEDIUM | 5.3 | 3.1% | Aug 1, 2023 | Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a... |
| CVE-2023-39110 | HIGH | 8.8 | 2.7% | Aug 1, 2023 | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPa... |
| CVE-2023-39109 | HIGH | 8.8 | 3.0% | Aug 1, 2023 | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Fun... |
| CVE-2023-39108 | HIGH | 8.8 | 3.0% | Aug 1, 2023 | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Fun... |
| CVE-2023-34634 | HIGH | 7.8 | 7.7% | Aug 1, 2023 | Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green... |
| CVE-2023-31710 | CRITICAL | 9.8 | 0.6% | Aug 1, 2023 | TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow... |
| CVE-2023-37478 | CRITICAL | 9.8 | 0.9% | Aug 1, 2023 | pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry ... |
| CVE-2023-32302 | — | — | — | Aug 1, 2023 | Rejected reason: Authoritative user requested CVE rejection https://github.com/github/advisory-database/pull/2575#issue... |
| CVE-2023-23548 | MEDIUM | 6.1 | 0.4% | Aug 1, 2023 | Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30. |
| CVE-2023-26139 | HIGH | 7.5 | 0.7% | Aug 1, 2023 | Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of th... |
| CVE-2023-36984 | HIGH | 7.5 | 0.6% | Aug 1, 2023 | LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. |
| CVE-2023-36983 | HIGH | 7.5 | 0.6% | Aug 1, 2023 | LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. |
| CVE-2023-34960 | CRITICAL | 9.8 | 99.4% | Aug 1, 2023 | A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex... |
| CVE-2023-4033 | HIGH | 7.8 | 1.2% | Aug 1, 2023 | OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0. |
| CVE-2023-37772 | HIGH | 8.8 | 0.8% | Aug 1, 2023 | Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /... |
| CVE-2023-37496 | MEDIUM | 5.4 | 0.3% | Aug 1, 2023 | HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a vi... |
| CVE-2023-3825 | HIGH | 7.5 | 0.8% | Jul 31, 2023 | PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now