2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3264 | CRITICAL | 9.8 | 0.5% | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactio... |
| CVE-2023-3259 | CRITICAL | 9.8 | 0.9% | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By man... |
| CVE-2023-39403 | CRITICAL | 9.1 | 0.3% | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san... |
| CVE-2023-39402 | CRITICAL | 9.1 | 0.4% | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san... |
| CVE-2023-39401 | CRITICAL | 9.1 | 0.4% | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san... |
| CVE-2023-39400 | CRITICAL | 9.1 | 0.4% | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san... |
| CVE-2023-39399 | CRITICAL | 9.1 | 0.3% | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san... |
| CVE-2023-39398 | CRITICAL | 9.1 | 0.3% | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san... |
| CVE-2023-39385 | CRITICAL | 9.1 | 0.3% | Aug 13, 2023 | Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnera... |
| CVE-2023-39405 | CRITICAL | 9.8 | 0.4% | Aug 13, 2023 | Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability m... |
| CVE-2023-3452 | CRITICAL | 9.8 | 5.6% | Aug 12, 2023 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w... |
| CVE-2023-40267 | CRITICAL | 9.8 | 1.0% | Aug 11, 2023 | GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists becau... |
| CVE-2023-40254 | CRITICAL | 9.8 | 0.2% | Aug 11, 2023 | Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Geni... |
| CVE-2023-40260 | CRITICAL | 9.1 | 0.5% | Aug 11, 2023 | EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first fa... |
| CVE-2023-40253 | CRITICAL | 9.8 | 0.4% | Aug 11, 2023 | Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0... |
| CVE-2023-3824 | CRITICAL | 9.8 | 8.0% | Aug 11, 2023 | In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading ... |
| CVE-2023-40256 | CRITICAL | 9.8 | 0.3% | Aug 11, 2023 | A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to i... |
| CVE-2023-27515 | CRITICAL | 9.6 | 0.5% | Aug 11, 2023 | Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potenti... |
| CVE-2023-25775 | CRITICAL | 9.8 | 1.0% | Aug 11, 2023 | Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an una... |
| CVE-2023-39806 | CRITICAL | 9.8 | 0.6% | Aug 10, 2023 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. |
| CVE-2023-39805 | CRITICAL | 9.8 | 0.6% | Aug 10, 2023 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. |
| CVE-2023-32565 | CRITICAL | 9.1 | 2.0% | Aug 10, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource... |
| CVE-2023-32564 | CRITICAL | 9.8 | 37.4% | Aug 10, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could... |
| CVE-2023-32563 | CRITICAL | 9.8 | 90.2% | Aug 10, 2023 | An unauthenticated attacker could achieve the code execution through a RemoteControl server. |
| CVE-2023-32562 | CRITICAL | 9.8 | 38.4% | Aug 10, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now