2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32437 | HIGH | 8.6 | 0.2% | Jul 27, 2023 | The issue was addressed with improvements to the file handling protocol. This issue is fixed in iOS 16.6 and iPadOS 16.6... |
| CVE-2023-32433 | HIGH | 7.8 | 0.3% | Jul 27, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS ... |
| CVE-2023-32381 | HIGH | 7.8 | 0.2% | Jul 27, 2023 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS ... |
| CVE-2023-28014 | MEDIUM | 5.4 | 0.2% | Jul 27, 2023 | HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scrip... |
| CVE-2023-28012 | HIGH | 8.8 | 0.8% | Jul 27, 2023 | HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell comma... |
| CVE-2023-3451 | — | — | — | Jul 26, 2023 | Rejected reason: Duplicate CVE. Please use CVE-2023-32297. |
| CVE-2023-28013 | MEDIUM | 6.1 | 0.3% | Jul 26, 2023 | HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering craf... |
| CVE-2023-38285 | HIGH | 7.5 | 0.8% | Jul 26, 2023 | Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity. |
| CVE-2023-37732 | MEDIUM | 5.5 | 0.3% | Jul 26, 2023 | Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacke... |
| CVE-2023-37692 | MEDIUM | 5.4 | 0.5% | Jul 26, 2023 | An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted fi... |
| CVE-2023-32001 | — | — | — | Jul 26, 2023 | Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem ... |
| CVE-2023-30367 | HIGH | 7.5 | 0.4% | Jul 26, 2023 | Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage mult... |
| CVE-2023-37624 | MEDIUM | 6.1 | 0.5% | Jul 26, 2023 | Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnera... |
| CVE-2023-37623 | MEDIUM | 4.8 | 0.5% | Jul 26, 2023 | Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/Ty... |
| CVE-2023-33802 | MEDIUM | 5.5 | 0.3% | Jul 26, 2023 | A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text fil... |
| CVE-2023-31466 | MEDIUM | 5.4 | 0.4% | Jul 26, 2023 | An XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance re... |
| CVE-2023-31465 | CRITICAL | 9.8 | 44.5% | Jul 26, 2023 | An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper st... |
| CVE-2023-3442 | HIGH | 7.5 | 0.6% | Jul 26, 2023 | A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 th... |
| CVE-2023-3414 | MEDIUM | 6.5 | 0.4% | Jul 26, 2023 | A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38... |
| CVE-2023-3242 | MEDIUM | 5.9 | 0.5% | Jul 26, 2023 | Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows ... |
| CVE-2023-30949 | MEDIUM | 5.3 | 0.2% | Jul 26, 2023 | A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which ... |
| CVE-2023-30577 | HIGH | 7.8 | 0.5% | Jul 26, 2023 | AMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for r... |
| CVE-2023-3622 | MEDIUM | 4.3 | 0.7% | Jul 26, 2023 | Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary r... |
| CVE-2023-33308 | CRITICAL | 9.8 | 1.9% | Jul 26, 2023 | A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 ... |
| CVE-2023-33229 | LOW | 3.5 | 0.8% | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now