CVEs from 2023

6,124 normalized CVEs published or assigned in this year.

Total
6,124
critical
critical 239
high
high 1,503
medium
medium 1,409
low
low 31
% Critical
3.9%
% with KEV
2.7%
% with exploit
3.5%

Top vendors

Top products

  • office 29
  • office_long_term_servicing_channel 15
  • 365_apps 14
  • ftmg-esr50sxx 8
  • ftmg-esn40sxx 8
  • ftmg-esd25axx 8
  • ftmg-esr40sxx 8
  • ftmg-esd15axx 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-20867 low 4.0 3y ago VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the…
CVE-2023-23814 low 3.8 3.8 2y ago Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar…
CVE-2023-28168 low 3.7 3.7 2y ago Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3…
CVE-2023-5831 low 3.7 3.7 3y ago An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.…
CVE-2023-38546 low 3.7 3.7 3y ago This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application crea…
CVE-2023-22049 low 3.7 3.7 3y ago RHSA-2023:4877: java-1.8.0-ibm security update (Moderate)
CVE-2023-22036 low 3.7 3.7 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2023-22045 low 3.7 3.7 3y ago RHSA-2023:4176: java-1.8.0-openjdk security and bug fix update (Moderate)
CVE-2023-21968 low 3.7 3.7 3y ago RHSA-2023:4103: java-1.8.0-ibm security update (Important)
CVE-2023-24375 low 3.5 3.5 2y ago Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This…
CVE-2023-29333 low 3.3 3.3 3y ago Microsoft Access Denial of Service Vulnerability
CVE-2023-22006 low 3.1 3.1 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2023-4752 low 2.5 1y ago Use After Free in GitHub repository vim/vim prior to 9.0.1858.
CVE-2023-45249 unknown 2.5 2y ago Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
CVE-2023-2953 low 2.5 2y ago RHSA-2024:4264: openldap security update (Low)
CVE-2023-43208 unknown 2.5 2y ago NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.
CVE-2023-7028 unknown 2.5 2y ago GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultima…
CVE-2023-32636 low 2.5 2y ago Low: mingw-glib2 security update
CVE-2023-6004 low 2.5 2y ago RHSA-2024:3233: libssh security update (Low)
CVE-2023-1729 low 2.5 2y ago Low: LibRaw security update
CVE-2023-6918 low 2.5 2y ago RHSA-2024:3233: libssh security update (Low)
CVE-2023-2975 low 2.5 2y ago Low: openssl and openssl-fips-provider security update
CVE-2023-3817 low 2.5 2y ago RHSA-2023:7877: openssl security update (Low)
CVE-2023-3446 low 2.5 2y ago RHSA-2024:0888: edk2 security update (Low)
CVE-2023-52620 low 2.5 2.5 2y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow timeout for anonymous sets Never used from userspace, disallow these parameters.
CVE-2023-24955 unknown 2.5 2y ago Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
CVE-2023-48788 unknown 2.5 2y ago Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
CVE-2023-3674 low 2.5 2y ago Low: keylime security update
CVE-2023-22527 unknown 2.5 2y ago Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
CVE-2023-29357 unknown 2.5 2y ago Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a netw…
CVE-2023-46805 unknown 2.5 2y ago Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to ac…
CVE-2023-23752 unknown 2.5 2y ago Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
CVE-2023-7101 unknown 2.5 2y ago Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Num…
CVE-2023-49103 unknown 2.5 3y ago ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.
CVE-2023-1671 unknown 2.5 3y ago Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
CVE-2023-36845 unknown 2.5 3y ago Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment var…
CVE-2023-4016 low 2.5 3y ago RHSA-2023:7187: procps-ng security update (Low)
CVE-2023-32573 low 2.5 3y ago In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
CVE-2023-32665 low 2.5 3y ago Low: glib2 security and bug fix update
CVE-2023-32611 low 2.5 3y ago Low: glib2 security and bug fix update
CVE-2023-29499 low 2.5 3y ago Low: glib2 security and bug fix update
CVE-2023-4641 low 2.5 3y ago RHSA-2023:7112: shadow-utils security and bug fix update (Low)
CVE-2023-22518 unknown 2.5 3y ago Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact …
CVE-2023-2977 low 2.5 3y ago RHSA-2023:7160: opensc security and bug fix update (Low)
CVE-2023-22745 low 2.5 3y ago RHSA-2023:7166: tpm2-tss security and enhancement update (Low)
CVE-2023-46747 unknown 2.5 3y ago F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network …
CVE-2023-46604 unknown 2.5 3y ago Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class type…
CVE-2023-20273 unknown 2.5 3y ago Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and writ…
CVE-2023-4966 unknown 2.5 3y ago Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, …
CVE-2023-20198 unknown 2.5 3y ago Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. Th…
CVE-2023-22515 unknown 2.5 3y ago Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
CVE-2023-40044 unknown 2.5 3y ago Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying oper…
CVE-2023-42793 unknown 2.5 3y ago JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
CVE-2023-38831 unknown 2.5 3y ago RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
CVE-2023-38035 unknown 2.5 3y ago Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to…
CVE-2023-3519 unknown 2.5 3y ago Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
CVE-2023-36874 unknown 2.5 3y ago Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-33246 unknown 2.5 3y ago Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using …
CVE-2023-20887 unknown 2.5 3y ago VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in …
CVE-2023-34362 unknown 2.5 3y ago Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engin…
CVE-2023-28771 unknown 2.5 3y ago Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets t…
CVE-2023-2868 unknown 2.5 3y ago Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection.
CVE-2023-32315 unknown 2.5 3y ago Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.
CVE-2023-29336 unknown 2.5 3y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.
CVE-2023-21839 unknown 2.5 3y ago Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
CVE-2023-1389 unknown 2.5 3y ago TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
CVE-2023-27524 unknown 2.5 3y ago Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altere…
CVE-2023-28432 unknown 2.5 3y ago MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.
CVE-2023-27350 unknown 2.5 3y ago PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.
CVE-2023-28252 unknown 2.5 3y ago Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-26360 unknown 2.5 3y ago Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2023-0669 unknown 2.5 3y ago Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
CVE-2023-22952 unknown 2.5 3y ago Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.
CVE-2023-27351 unknown 1.5 2mo ago PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
CVE-2023-36424 unknown 1.5 2mo ago Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CVE-2023-21529 unknown 1.5 2mo ago Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2023-41974 unknown 1.5 3mo ago Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
CVE-2023-52163 unknown 1.5 5mo ago Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
CVE-2023-50224 unknown 1.5 9mo ago TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The imp…
CVE-2023-2533 unknown 1.5 10mo ago PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.
CVE-2023-33538 unknown 1.5 1y ago TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) an…
CVE-2023-39780 unknown 1.5 1y ago ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
CVE-2023-38950 unknown 1.5 1y ago ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.
CVE-2023-44221 unknown 1.5 1y ago SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbi…
CVE-2023-20118 unknown 1.5 1y ago Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker…
CVE-2023-34192 unknown 1.5 1y ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoS…
CVE-2023-48365 unknown 1.5 1y ago Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
CVE-2023-45727 unknown 1.5 2y ago North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated at…
CVE-2023-28461 unknown 1.5 2y ago Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
CVE-2023-25280 unknown 1.5 2y ago D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter t…
CVE-2023-21237 unknown 1.5 2y ago Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a loc…
CVE-2023-29360 unknown 1.5 2y ago Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
CVE-2023-43770 unknown 1.5 2y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
CVE-2023-4762 unknown 1.5 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Ch…
CVE-2023-34048 unknown 1.5 2y ago VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
CVE-2023-35082 unknown 1.5 2y ago Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the applicat…
CVE-2023-6548 unknown 1.5 2y ago Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
CVE-2023-6549 unknown 1.5 2y ago Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or…
CVE-2023-29300 unknown 1.5 2y ago Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-41990 unknown 1.5 2y ago Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.