2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2798HIGH7.5Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is r...
CVE-2023-2480HIGH7.8Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation ...
CVE-2023-22504MEDIUM6.5Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not wri...
CVE-2023-0459MEDIUM5.5Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to b...
CVE-2023-2888HIGH8.8A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the fi...
CVE-2023-30484HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in uPress Enable Accessibility plugin <= 1.4 versions.
CVE-2023-28370MEDIUM6.1Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a...
CVE-2023-27529HIGH7.8Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulne...
CVE-2023-2887CRITICAL9.8Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbo...
CVE-2023-2886MEDIUM4.3Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipu...
CVE-2023-2885HIGH8.1Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot a...
CVE-2023-2884CRITICAL9.8Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability i...
CVE-2023-2883HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authenticati...
CVE-2023-2882CRITICAL9.8Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This...
CVE-2023-2881MEDIUM4.9Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
CVE-2023-1588Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-2734CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This...
CVE-2023-2733CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This...
CVE-2023-2732CRITICAL9.8The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This...
CVE-2023-31861HIGH7.5ZLMediaKit 4.0 is vulnerable to Directory Traversal.
CVE-2023-31594HIGH7.5IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.
CVE-2023-2500HIGH8.8The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versi...
CVE-2023-1601Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-33248HIGH7.6Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attack...
CVE-2023-1158MEDIUM4.3 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now