2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28764 | MEDIUM | 5.9 | 0.5% | May 9, 2023 | SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext i... |
| CVE-2023-28762 | HIGH | 7.2 | 0.7% | May 9, 2023 | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administra... |
| CVE-2023-22813 | MEDIUM | 4.3 | 0.5% | May 8, 2023 | A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps,... |
| CVE-2023-22710 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCom... |
| CVE-2023-24376 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0 versions. |
| CVE-2023-23894 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Surbma Surbma | GDPR Proof Cookie Consent & Noti... |
| CVE-2023-31183 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using ... |
| CVE-2023-31182 | CRITICAL | 9.8 | 0.6% | May 8, 2023 | EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified meth... |
| CVE-2023-31181 | HIGH | 7.5 | 0.7% | May 8, 2023 | WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal |
| CVE-2023-31180 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - Reflected cross-site scripting (RXSS) through an unspecified reque... |
| CVE-2023-31179 | HIGH | 7.5 | 0.7% | May 8, 2023 | AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal - Vulnerability allows path traversal and downloading files from the s... |
| CVE-2023-31178 | CRITICAL | 9.1 | 0.6% | May 8, 2023 | AgilePoint NX v8.0 SU2.2 & SU2.3 – Arbitrary File Delete Vulnerability allows arbitrary file deletion, by an unspecified... |
| CVE-2023-31141 | MEDIUM | 5.9 | 0.5% | May 8, 2023 | OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10... |
| CVE-2023-31140 | MEDIUM | 6.5 | 0.9% | May 8, 2023 | OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a ... |
| CVE-2023-31133 | HIGH | 7.5 | 45.7% | May 8, 2023 | Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid ... |
| CVE-2023-31129 | CRITICAL | 9.8 | 0.6% | May 8, 2023 | The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message han... |
| CVE-2023-31127 | HIGH | 8.8 | 0.9% | May 8, 2023 | libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPD... |
| CVE-2023-31125 | MEDIUM | 6.5 | 1.3% | May 8, 2023 | Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc... |
| CVE-2023-31123 | CRITICAL | 9.1 | 0.6% | May 8, 2023 | `effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior t... |
| CVE-2023-30334 | MEDIUM | 6.1 | 0.6% | May 8, 2023 | AsmBB v2.9.1 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the MiniMag.asm and bbcod... |
| CVE-2023-2582 | MEDIUM | 6.1 | 0.6% | May 8, 2023 | A prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in... |
| CVE-2023-2513 | MEDIUM | 6.7 | 0.2% | May 8, 2023 | A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode siz... |
| CVE-2023-2478 | MEDIUM | 6.5 | 5.0% | May 8, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions start... |
| CVE-2023-24507 | CRITICAL | 9.8 | 0.7% | May 8, 2023 | AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecifie... |
| CVE-2023-24506 | HIGH | 7.5 | 0.6% | May 8, 2023 | Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now