2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21487 | LOW | 3.3 | 0.1% | May 4, 2023 | Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to c... |
| CVE-2023-21486 | MEDIUM | 4.6 | 0.3% | May 4, 2023 | Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023... |
| CVE-2023-21485 | MEDIUM | 4.6 | 0.3% | May 4, 2023 | Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023... |
| CVE-2023-21484 | HIGH | 7.8 | 0.1% | May 4, 2023 | Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper p... |
| CVE-2023-31284 | HIGH | 7.8 | 0.3% | May 4, 2023 | illumos illumos-gate before 676abcb has a stack buffer overflow in /dev/net, leading to privilege escalation via a stat ... |
| CVE-2023-30268 | CRITICAL | 9.8 | 0.8% | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Improper Input Validation. |
| CVE-2023-30264 | CRITICAL | 9.8 | 0.7% | May 4, 2023 | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.... |
| CVE-2023-30097 | MEDIUM | 5.4 | 0.7% | May 4, 2023 | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitr... |
| CVE-2023-30096 | MEDIUM | 5.4 | 0.7% | May 4, 2023 | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitr... |
| CVE-2023-30095 | MEDIUM | 5.4 | 0.7% | May 4, 2023 | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitr... |
| CVE-2023-30094 | MEDIUM | 5.4 | 0.7% | May 4, 2023 | A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts ... |
| CVE-2023-25982 | MEDIUM | 5.4 | 0.4% | May 4, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5 v... |
| CVE-2023-25977 | MEDIUM | 4.8 | 0.4% | May 4, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 9seeds.Com CPT – Speakers plugin <= 1.1 versions. |
| CVE-2023-25961 | MEDIUM | 6.1 | 0.4% | May 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Catch Themes Darcie theme <= 1.1.5 versions. |
| CVE-2023-25458 | MEDIUM | 4.8 | 0.4% | May 4, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GMO Internet Group, Inc. TypeSquare Webfonts for ConoH... |
| CVE-2023-23059 | CRITICAL | 9.8 | 1.5% | May 4, 2023 | An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions ... |
| CVE-2023-20126 | CRITICAL | 9.8 | 38.1% | May 4, 2023 | A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticat... |
| CVE-2023-2524 | CRITICAL | 9.8 | 0.4% | May 4, 2023 | A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the ... |
| CVE-2023-30550 | MEDIUM | 4.5 | 0.7% | May 4, 2023 | MeterSphere is an open source continuous testing platform, covering functions such as test tracking, interface testing, ... |
| CVE-2023-2523 | CRITICAL | 9.8 | 32.9% | May 4, 2023 | A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown ... |
| CVE-2023-2522 | HIGH | 7.2 | 36.0% | May 4, 2023 | A vulnerability was found in Chengdu VEC40G 3.0. It has been declared as critical. Affected by this vulnerability is an ... |
| CVE-2023-30203 | CRITICAL | 9.8 | 0.8% | May 4, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /ph... |
| CVE-2023-30184 | MEDIUM | 5.4 | 0.4% | May 4, 2023 | A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or... |
| CVE-2023-2521 | LOW | 3.5 | 0.3% | May 4, 2023 | A vulnerability was found in NEXTU NEXT-7004N 3.0.1. It has been classified as problematic. Affected is an unknown funct... |
| CVE-2023-2520 | CRITICAL | 9.8 | 2.6% | May 4, 2023 | A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affect... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now