2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49115 | HIGH | 7.5 | 0.6% | Feb 1, 2024 | MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by u... |
| CVE-2023-47867 | HIGH | 8.8 | 0.4% | Feb 1, 2024 | MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect... |
| CVE-2023-36496 | HIGH | 8.8 | 0.5% | Feb 1, 2024 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their... |
| CVE-2023-47257 | HIGH | 8.1 | 1.0% | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted... |
| CVE-2023-51446 | HIGH | 8.1 | 0.9% | Feb 1, 2024 | GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication ... |
| CVE-2023-51939 | HIGH | 8.8 | 0.9% | Feb 1, 2024 | An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker... |
| CVE-2023-28807 | HIGH | 7.5 | 0.3% | Jan 31, 2024 | In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables... |
| CVE-2023-50165 | HIGH | 8.6 | 0.3% | Jan 31, 2024 | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. |
| CVE-2023-6779 | HIGH | 7.5 | 3.1% | Jan 31, 2024 | An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This functio... |
| CVE-2023-6246 | HIGH | 7.8 | 4.8% | Jan 31, 2024 | A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called ... |
| CVE-2023-44313 | HIGH | 7.5 | 3.5% | Jan 31, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive se... |
| CVE-2023-44312 | HIGH | 7.5 | 0.8% | Jan 31, 2024 | Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apa... |
| CVE-2023-31505 | HIGH | 7.2 | 1.2% | Jan 31, 2024 | An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrar... |
| CVE-2023-5389 | HIGH | 7.5 | 0.8% | Jan 30, 2024 | An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ... |
| CVE-2023-6258 | HIGH | 8.1 | 0.6% | Jan 30, 2024 | A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography St... |
| CVE-2023-46231 | HIGH | 7.2 | 0.5% | Jan 30, 2024 | In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when... |
| CVE-2023-37518 | HIGH | 8.8 | 0.4% | Jan 30, 2024 | HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary... |
| CVE-2023-6942 | HIGH | 7.5 | 0.9% | Jan 30, 2024 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5... |
| CVE-2023-6374 | HIGH | 7.5 | 0.8% | Jan 30, 2024 | Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 ... |
| CVE-2023-36260 | HIGH | 7.5 | 1.1% | Jan 30, 2024 | An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of servi... |
| CVE-2023-5372 | HIGH | 7.2 | 28.5% | Jan 30, 2024 | The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and N... |
| CVE-2023-51843 | HIGH | 8.2 | 0.5% | Jan 30, 2024 | react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set. |
| CVE-2023-4552 | HIGH | 7.1 | 0.4% | Jan 29, 2024 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenti... |
| CVE-2023-4551 | HIGH | 8.8 | 1.0% | Jan 29, 2024 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBu... |
| CVE-2023-4550 | HIGH | 7.5 | 0.5% | Jan 29, 2024 | Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on W... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now