2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49038 | HIGH | 7.2 | 1.8% | Jan 29, 2024 | Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbit... |
| CVE-2023-51842 | HIGH | 7.5 | 0.8% | Jan 29, 2024 | An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16. |
| CVE-2023-1705 | HIGH | 7.8 | 0.1% | Jan 29, 2024 | Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) all... |
| CVE-2023-7204 | HIGH | 7.5 | 0.6% | Jan 29, 2024 | The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provid... |
| CVE-2023-7074 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2023-6946 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2023-6391 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2023-6390 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2023-6279 | HIGH | 7.1 | 0.5% | Jan 29, 2024 | The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any aut... |
| CVE-2023-40548 | HIGH | 7.4 | 0.4% | Jan 29, 2024 | A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a ... |
| CVE-2023-29055 | HIGH | 7.5 | 1.1% | Jan 29, 2024 | In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.... |
| CVE-2023-46838 | HIGH | 7.5 | 1.2% | Jan 29, 2024 | Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for ... |
| CVE-2023-6200 | HIGH | 7.5 | 2.1% | Jan 28, 2024 | A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent n... |
| CVE-2023-52187 | HIGH | 7.5 | 0.5% | Jan 27, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Thomas Maier Image Source Control Lite – Sho... |
| CVE-2023-6291 | HIGH | 7.1 | 0.9% | Jan 26, 2024 | A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly... |
| CVE-2023-6919 | HIGH | 7.5 | 0.6% | Jan 26, 2024 | Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path... |
| CVE-2023-51833 | HIGH | 8.1 | 4.4% | Jan 25, 2024 | A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code vi... |
| CVE-2023-52251 | HIGH | 8.8 | 85.0% | Jan 25, 2024 | An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the ... |
| CVE-2023-52356 | HIGH | 7.5 | 2.2% | Jan 25, 2024 | A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadR... |
| CVE-2023-52355 | HIGH | 7.5 | 1.7% | Jan 25, 2024 | An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanl... |
| CVE-2023-52076 | HIGH | 7.8 | 1.0% | Jan 25, 2024 | Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arb... |
| CVE-2023-40547 | HIGH | 8.3 | 4.9% | Jan 25, 2024 | A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when pa... |
| CVE-2023-3181 | HIGH | 7.8 | 0.2% | Jan 25, 2024 | The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~n... |
| CVE-2023-24676 | HIGH | 7.2 | 1.3% | Jan 24, 2024 | An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the dow... |
| CVE-2023-51890 | HIGH | 7.5 | 0.9% | Jan 24, 2024 | An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via craf... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now