2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6724 | HIGH | 8.8 | 0.6% | Feb 9, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Lim... |
| CVE-2023-51761 | HIGH | 8.1 | 0.7% | Feb 9, 2024 | In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass a... |
| CVE-2023-45191 | HIGH | 7.5 | 0.7% | Feb 9, 2024 | IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a rem... |
| CVE-2023-45187 | HIGH | 8.8 | 0.4% | Feb 9, 2024 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could... |
| CVE-2023-47131 | HIGH | 7.5 | 0.5% | Feb 8, 2024 | The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file. |
| CVE-2023-40263 | HIGH | 8.8 | 1.2% | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated comman... |
| CVE-2023-40265 | HIGH | 8.8 | 0.9% | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenti... |
| CVE-2023-27001 | HIGH | 8.8 | 0.9% | Feb 8, 2024 | An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the... |
| CVE-2023-25365 | HIGH | 7.8 | 0.4% | Feb 8, 2024 | Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the ... |
| CVE-2023-47020 | HIGH | 8.8 | 0.3% | Feb 8, 2024 | Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by... |
| CVE-2023-6519 | HIGH | 7.5 | 0.5% | Feb 8, 2024 | Exposure of Data Element to Wrong Session vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Wit... |
| CVE-2023-6518 | HIGH | 7.5 | 0.4% | Feb 8, 2024 | Plaintext Storage of a Password vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Exe... |
| CVE-2023-6517 | HIGH | 7.5 | 0.5% | Feb 8, 2024 | Exposure of Sensitive Information Due to Incompatible Policies vulnerability in Mia Technology Inc. MİA-MED allows Colle... |
| CVE-2023-6515 | HIGH | 8.8 | 0.6% | Feb 8, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abus... |
| CVE-2023-6536 | HIGH | 7.5 | 1.5% | Feb 7, 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se... |
| CVE-2023-6535 | HIGH | 7.5 | 1.5% | Feb 7, 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se... |
| CVE-2023-6356 | HIGH | 7.5 | 1.4% | Feb 7, 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a se... |
| CVE-2023-47700 | HIGH | 7.5 | 0.5% | Feb 7, 2024 | IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote at... |
| CVE-2023-43017 | HIGH | 7.2 | 0.6% | Feb 7, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that ... |
| CVE-2023-38369 | HIGH | 7.5 | 0.5% | Feb 7, 2024 | IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong p... |
| CVE-2023-51437 | HIGH | 7.4 | 0.8% | Feb 7, 2024 | Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge... |
| CVE-2023-45735 | HIGH | 8 | 0.5% | Feb 6, 2024 | A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affec... |
| CVE-2023-38579 | HIGH | 8.8 | 0.2% | Feb 6, 2024 | The cross-site request forgery token in the request may be predictable or easily guessable allowing attacke... |
| CVE-2023-47618 | HIGH | 7.2 | 1.9% | Feb 6, 2024 | A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada ... |
| CVE-2023-47617 | HIGH | 7.2 | 3.4% | Feb 6, 2024 | A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Oma... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now