2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30177 | MEDIUM | 6.1 | 0.4% | Apr 25, 2023 | CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name. |
| CVE-2023-29200 | MEDIUM | 6.5 | 0.8% | Apr 25, 2023 | Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can li... |
| CVE-2023-23838 | MEDIUM | 6.5 | 1.3% | Apr 25, 2023 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the serv... |
| CVE-2023-23837 | HIGH | 7.5 | 0.8% | Apr 25, 2023 | No exception handling vulnerability which revealed sensitive or excessive information to users. |
| CVE-2023-28847 | HIGH | 7.5 | 0.8% | Apr 25, 2023 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.... |
| CVE-2023-25484 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 v... |
| CVE-2023-30402 | MEDIUM | 5.5 | 0.3% | Apr 25, 2023 | YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: Th... |
| CVE-2023-29552 | HIGH | 7.5 | 65.9% | Apr 25, 2023 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.... |
| CVE-2023-25314 | MEDIUM | 6.1 | 0.4% | Apr 25, 2023 | Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain se... |
| CVE-2023-25313 | CRITICAL | 9.8 | 1.3% | Apr 25, 2023 | OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbit... |
| CVE-2023-27105 | CRITICAL | 9.8 | 1.3% | Apr 25, 2023 | A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and... |
| CVE-2023-2281 | MEDIUM | 4.3 | 0.5% | Apr 25, 2023 | When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. Thi... |
| CVE-2023-29779 | HIGH | 7.5 | 1.2% | Apr 25, 2023 | Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send ma... |
| CVE-2023-30417 | MEDIUM | 5.4 | 0.4% | Apr 25, 2023 | A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scr... |
| CVE-2023-26843 | MEDIUM | 5.4 | 1.4% | Apr 25, 2023 | A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr... |
| CVE-2023-26841 | MEDIUM | 6.5 | 0.4% | Apr 25, 2023 | A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password exc... |
| CVE-2023-26840 | MEDIUM | 5.3 | 0.3% | Apr 25, 2023 | A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set... |
| CVE-2023-26839 | MEDIUM | 4.3 | 0.3% | Apr 25, 2023 | A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing ... |
| CVE-2023-26058 | MEDIUM | 6.5 | 0.5% | Apr 25, 2023 | An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input va... |
| CVE-2023-26057 | MEDIUM | 6.5 | 0.5% | Apr 25, 2023 | An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. In... |
| CVE-2023-25348 | HIGH | 7.8 | 0.4% | Apr 25, 2023 | ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields wh... |
| CVE-2023-25347 | MEDIUM | 5.4 | 0.6% | Apr 25, 2023 | A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web sc... |
| CVE-2023-25346 | MEDIUM | 6.1 | 1.5% | Apr 25, 2023 | A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web ... |
| CVE-2023-27619 | MEDIUM | 5.4 | 0.4% | Apr 25, 2023 | Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 version... |
| CVE-2023-26098 | HIGH | 7.8 | 0.2% | Apr 25, 2023 | An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now