2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28009 | HIGH | 8.1 | 0.8% | Apr 26, 2023 | HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remot... |
| CVE-2023-28008 | HIGH | 8.1 | 0.8% | Apr 26, 2023 | HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processi... |
| CVE-2023-27559 | HIGH | 7.5 | 0.9% | Apr 26, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv... |
| CVE-2023-26567 | HIGH | 8.1 | 0.6% | Apr 26, 2023 | Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPAS... |
| CVE-2023-31250 | MEDIUM | 6.5 | 0.5% | Apr 26, 2023 | The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gain... |
| CVE-2023-30841 | MEDIUM | 5.5 | 0.2% | Apr 26, 2023 | Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic an... |
| CVE-2023-30546 | HIGH | 7.5 | 0.6% | Apr 26, 2023 | Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope d... |
| CVE-2023-26938 | — | — | — | Apr 26, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio... |
| CVE-2023-26937 | — | — | — | Apr 26, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio... |
| CVE-2023-26936 | — | — | — | Apr 26, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio... |
| CVE-2023-26935 | — | — | — | Apr 26, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio... |
| CVE-2023-26934 | — | — | — | Apr 26, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio... |
| CVE-2023-26931 | — | — | — | Apr 26, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2022-30524. Reason: This record is a duplicate of CVE-2022-... |
| CVE-2023-26930 | MEDIUM | 5.5 | 0.3% | Apr 26, 2023 | Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc... |
| CVE-2023-0458 | MEDIUM | 4.7 | 0.7% | Apr 26, 2023 | A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument... |
| CVE-2023-29268 | CRITICAL | 9.8 | 1.0% | Apr 26, 2023 | The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that all... |
| CVE-2023-30212 | MEDIUM | 6.1 | 8.1% | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php. |
| CVE-2023-2307 | MEDIUM | 6.5 | 0.3% | Apr 26, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0. |
| CVE-2023-30211 | CRITICAL | 9.8 | 1.0% | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerable to SQL Injection. |
| CVE-2023-30210 | MEDIUM | 6.1 | 1.2% | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerable to Cross Site Scripting (XSS) via ourphp_tz.php. |
| CVE-2023-22729 | MEDIUM | 6.1 | 0.4% | Apr 26, 2023 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr... |
| CVE-2023-30269 | HIGH | 8.1 | 0.7% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php. |
| CVE-2023-30267 | MEDIUM | 6.1 | 0.4% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Cross Site Scripting (XSS) via application/home/controller/Changyan.php. |
| CVE-2023-30266 | HIGH | 8.8 | 0.8% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. |
| CVE-2023-30265 | MEDIUM | 6.5 | 1.0% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Directory Traversal. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now