2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50437 | HIGH | 8.6 | 0.7% | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/defau... |
| CVE-2023-38372 | HIGH | 7.5 | 0.6% | Feb 29, 2024 | An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to imp... |
| CVE-2023-34198 | HIGH | 7.3 | 0.5% | Feb 29, 2024 | In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 th... |
| CVE-2023-25926 | HIGH | 8.2 | 1.4% | Feb 29, 2024 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Inje... |
| CVE-2023-25921 | HIGH | 8.8 | 1.1% | Feb 29, 2024 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer f... |
| CVE-2023-49338 | HIGH | 7.5 | 0.6% | Feb 28, 2024 | Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals end... |
| CVE-2023-45859 | HIGH | 7.6 | 0.5% | Feb 28, 2024 | In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through... |
| CVE-2023-25925 | HIGH | 8.8 | 1.4% | Feb 28, 2024 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker ... |
| CVE-2023-25922 | HIGH | 8.8 | 0.6% | Feb 28, 2024 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer fi... |
| CVE-2023-52047 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager. |
| CVE-2023-52226 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a thro... |
| CVE-2023-52223 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects Ma... |
| CVE-2023-51683 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects... |
| CVE-2023-51747 | HIGH | 7.1 | 1.0% | Feb 27, 2024 | Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter h... |
| CVE-2023-7016 | HIGH | 7.8 | 0.3% | Feb 27, 2024 | A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYST... |
| CVE-2023-5993 | HIGH | 7.8 | 0.2% | Feb 27, 2024 | A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker ... |
| CVE-2023-7165 | HIGH | 7.5 | 1.9% | Feb 27, 2024 | The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive d... |
| CVE-2023-6585 | HIGH | 7.5 | 0.6% | Feb 27, 2024 | The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated... |
| CVE-2023-6584 | HIGH | 7.5 | 0.5% | Feb 27, 2024 | The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only kno... |
| CVE-2023-50379 | HIGH | 8.8 | 1.1% | Feb 27, 2024 | Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fi... |
| CVE-2023-36237 | HIGH | 8.8 | 0.4% | Feb 26, 2024 | Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a cr... |
| CVE-2023-52474 | HIGH | 7.8 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iove... |
| CVE-2023-52469 | HIGH | 7.8 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_po... |
| CVE-2023-52468 | HIGH | 7.8 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: class: fix use-after-free in class_register() The ... |
| CVE-2023-49960 | HIGH | 7.5 | 0.7% | Feb 26, 2024 | In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmwa... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now