2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6452 | CRITICAL | 9.6 | 0.4% | Aug 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Sec... |
| CVE-2023-0714 | CRITICAL | 9.8 | 1.0% | Aug 17, 2024 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file... |
| CVE-2023-20591 | CRITICAL | 10 | 0.3% | Aug 13, 2024 | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, all... |
| CVE-2023-26211 | CRITICAL | 9 | 0.7% | Aug 13, 2024 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 thro... |
| CVE-2023-7249 | CRITICAL | 9.8 | 0.6% | Aug 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Direct... |
| CVE-2023-48396 | CRITICAL | 9.1 | 0.7% | Jul 30, 2024 | Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can... |
| CVE-2023-45249 | CRITICAL | 9.8 | 53.5% | Jul 24, 2024 | Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct... |
| CVE-2023-40704 | CRITICAL | 9.8 | 0.3% | Jul 18, 2024 | The product does not require unique and complex passwords to be created during installation. Using Philips's default pa... |
| CVE-2023-4976 | CRITICAL | 9.3 | 0.4% | Jul 17, 2024 | A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an un... |
| CVE-2023-7012 | CRITICAL | 9.6 | 0.3% | Jul 16, 2024 | Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convi... |
| CVE-2023-4860 | CRITICAL | 9.6 | 0.4% | Jul 16, 2024 | Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromis... |
| CVE-2023-48194 | CRITICAL | 9.8 | 0.8% | Jul 9, 2024 | Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After exec... |
| CVE-2023-46685 | CRITICAL | 9.8 | 1.0% | Jul 8, 2024 | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_1... |
| CVE-2023-24531 | CRITICAL | 9.8 | 0.8% | Jul 2, 2024 | Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitiz... |
| CVE-2023-41921 | CRITICAL | 9.8 | 0.3% | Jul 2, 2024 | A vulnerability allows attackers to download source code or an executable from a remote location and execute the code wi... |
| CVE-2023-41920 | CRITICAL | 9.8 | 0.4% | Jul 2, 2024 | The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the devic... |
| CVE-2023-41919 | CRITICAL | 9.8 | 0.4% | Jul 2, 2024 | Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauth... |
| CVE-2023-41918 | CRITICAL | 10 | 0.6% | Jul 2, 2024 | A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this... |
| CVE-2023-41917 | CRITICAL | 10 | 0.7% | Jul 2, 2024 | Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit thi... |
| CVE-2023-6198 | CRITICAL | 9.3 | 0.4% | Jun 25, 2024 | Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows ... |
| CVE-2023-50029 | CRITICAL | 10 | 0.8% | Jun 24, 2024 | PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaSh... |
| CVE-2023-45673 | CRITICAL | 9 | 1.0% | Jun 21, 2024 | Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected... |
| CVE-2023-38389 | CRITICAL | 9.8 | 1.2% | Jun 21, 2024 | Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained b... |
| CVE-2023-45197 | CRITICAL | 9.8 | 0.7% | Jun 21, 2024 | The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the ro... |
| CVE-2023-36515 | CRITICAL | 9.8 | 0.4% | Jun 19, 2024 | Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now