2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26847 | MEDIUM | 5.4 | 0.4% | Apr 11, 2023 | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts o... |
| CVE-2023-26846 | MEDIUM | 5.4 | 0.4% | Apr 11, 2023 | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts o... |
| CVE-2023-26845 | MEDIUM | 4.3 | 0.2% | Apr 11, 2023 | A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via u... |
| CVE-2023-23277 | MEDIUM | 6.1 | 0.7% | Apr 11, 2023 | Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML ... |
| CVE-2023-1552 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI ... |
| CVE-2023-28062 | HIGH | 8.8 | 0.8% | Apr 11, 2023 | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated mal... |
| CVE-2023-26964 | HIGH | 7.5 | 1.1% | Apr 11, 2023 | An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STRE... |
| CVE-2023-0645 | CRITICAL | 9.1 | 0.6% | Apr 11, 2023 | An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read ... |
| CVE-2023-27645 | CRITICAL | 9.8 | 1.5% | Apr 11, 2023 | An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges v... |
| CVE-2023-27179 | HIGH | 7.5 | 60.8% | Apr 11, 2023 | GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet... |
| CVE-2023-26917 | HIGH | 7.5 | 0.9% | Apr 11, 2023 | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validat... |
| CVE-2023-1976 | HIGH | 8.8 | 0.6% | Apr 11, 2023 | Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-29054 | HIGH | 7.4 | 0.3% | Apr 11, 2023 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions ... |
| CVE-2023-29053 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | A vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The ... |
| CVE-2023-28828 | MEDIUM | 5.9 | 0.6% | Apr 11, 2023 | A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Enti... |
| CVE-2023-28766 | HIGH | 7.5 | 0.9% | Apr 11, 2023 | A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300... |
| CVE-2023-28489 | CRITICAL | 9.8 | 2.8% | Apr 11, 2023 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver... |
| CVE-2023-27464 | MEDIUM | 5.3 | 0.5% | Apr 11, 2023 | A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forg... |
| CVE-2023-26293 | HIGH | 7.3 | 0.2% | Apr 11, 2023 | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Int... |
| CVE-2023-23588 | MEDIUM | 6.3 | 0.1% | Apr 11, 2023 | A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Stora... |
| CVE-2023-1975 | MEDIUM | 6.5 | 0.6% | Apr 11, 2023 | Insertion of Sensitive Information Into Sent Data in GitHub repository answerdev/answer prior to 1.0.8. |
| CVE-2023-1974 | MEDIUM | 6.5 | 0.6% | Apr 11, 2023 | Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8. |
| CVE-2023-28368 | MEDIUM | 5.7 | 0.3% | Apr 11, 2023 | TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH h... |
| CVE-2023-27917 | HIGH | 8.8 | 1.9% | Apr 11, 2023 | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can acce... |
| CVE-2023-27520 | MEDIUM | 6.5 | 0.3% | Apr 11, 2023 | Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote una... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now