2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28473 | LOW | 3.3 | 0.8% | Apr 28, 2023 | Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypa... |
| CVE-2023-28472 | MEDIUM | 5.3 | 0.6% | Apr 28, 2023 | Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only ... |
| CVE-2023-28471 | MEDIUM | 5.4 | 0.5% | Apr 28, 2023 | Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name. |
| CVE-2023-30024 | MEDIUM | 6.6 | 0.5% | Apr 28, 2023 | The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing u... |
| CVE-2023-2369 | CRITICAL | 9.8 | 0.7% | Apr 28, 2023 | A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been rated as critical. This issue aff... |
| CVE-2023-2368 | CRITICAL | 9.8 | 0.7% | Apr 28, 2023 | A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been declared as critical. This vulner... |
| CVE-2023-2367 | CRITICAL | 9.8 | 0.7% | Apr 28, 2023 | A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been classified as critical. This affe... |
| CVE-2023-2366 | CRITICAL | 9.8 | 0.8% | Apr 28, 2023 | A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this i... |
| CVE-2023-2365 | CRITICAL | 9.8 | 0.7% | Apr 28, 2023 | A vulnerability has been found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by t... |
| CVE-2023-2360 | HIGH | 7.5 | 0.4% | Apr 28, 2023 | Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infras... |
| CVE-2023-30467 | CRITICAL | 9.8 | 1.1% | Apr 28, 2023 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xx... |
| CVE-2023-30466 | CRITICAL | 9.8 | 1.1% | Apr 28, 2023 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xx... |
| CVE-2023-2364 | MEDIUM | 5.4 | 0.8% | Apr 28, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Resort Reservation System 1.0. Affecte... |
| CVE-2023-2363 | CRITICAL | 9.8 | 0.8% | Apr 28, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This ... |
| CVE-2023-2361 | MEDIUM | 5.4 | 0.5% | Apr 28, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. |
| CVE-2023-28882 | HIGH | 7.5 | 0.7% | Apr 28, 2023 | Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) be... |
| CVE-2023-28528 | HIGH | 7.8 | 1.5% | Apr 28, 2023 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c... |
| CVE-2023-31436 | HIGH | 7.8 | 0.6% | Apr 28, 2023 | qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can... |
| CVE-2023-27557 | HIGH | 7.5 | 0.4% | Apr 28, 2023 | IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6... |
| CVE-2023-27556 | HIGH | 7.5 | 1.0% | Apr 28, 2023 | IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02... |
| CVE-2023-2356 | HIGH | 7.5 | 4.2% | Apr 28, 2023 | Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1. |
| CVE-2023-29169 | HIGH | 8.8 | 0.7% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-29150 | HIGH | 8.8 | 0.7% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-28716 | HIGH | 8.8 | 4.5% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
| CVE-2023-28400 | HIGH | 8.8 | 24.6% | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now