2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1185 | HIGH | 8.8 | 0.7% | Mar 6, 2023 | A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of t... |
| CVE-2023-1184 | HIGH | 8.8 | 0.7% | Mar 6, 2023 | A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is so... |
| CVE-2023-0839 | CRITICAL | 9.8 | 0.6% | Mar 6, 2023 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Acc... |
| CVE-2023-22858 | MEDIUM | 5.3 | 0.4% | Mar 6, 2023 | An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files ... |
| CVE-2023-22857 | MEDIUM | 5.4 | 0.4% | Mar 6, 2023 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in... |
| CVE-2023-22856 | MEDIUM | 5.4 | 0.4% | Mar 6, 2023 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in... |
| CVE-2023-26111 | HIGH | 7.5 | 1.5% | Mar 6, 2023 | All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directo... |
| CVE-2023-26108 | MEDIUM | 5.3 | 0.7% | Mar 6, 2023 | Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Ex... |
| CVE-2023-26107 | HIGH | 7.8 | 0.4% | Mar 6, 2023 | All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without saniti... |
| CVE-2023-26106 | HIGH | 7.5 | 0.9% | Mar 6, 2023 | All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file. |
| CVE-2023-25077 | MEDIUM | 5.4 | 0.6% | Mar 6, 2023 | Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p... |
| CVE-2023-22838 | MEDIUM | 5.4 | 0.5% | Mar 6, 2023 | Cross-site scripting vulnerability in Product List Screen and Product Detail Screen of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUB... |
| CVE-2023-22438 | MEDIUM | 5.4 | 0.7% | Mar 6, 2023 | Cross-site scripting vulnerability in Contents Management of EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 ... |
| CVE-2023-22432 | MEDIUM | 6.1 | 2.4% | Mar 6, 2023 | Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirec... |
| CVE-2023-22424 | HIGH | 7.8 | 0.3% | Mar 6, 2023 | Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Vers... |
| CVE-2023-22421 | HIGH | 7.8 | 0.3% | Mar 6, 2023 | Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ... |
| CVE-2023-22419 | HIGH | 7.8 | 0.2% | Mar 6, 2023 | Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ... |
| CVE-2023-22344 | CRITICAL | 9.8 | 0.9% | Mar 6, 2023 | Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and e... |
| CVE-2023-22336 | CRITICAL | 9.8 | 1.1% | Mar 6, 2023 | Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a... |
| CVE-2023-22335 | HIGH | 7.5 | 0.7% | Mar 6, 2023 | Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier... |
| CVE-2023-27641 | MEDIUM | 6.1 | 1.1% | Mar 5, 2023 | The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XS... |
| CVE-2023-27635 | HIGH | 7.8 | 0.4% | Mar 5, 2023 | debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a cr... |
| CVE-2023-26510 | MEDIUM | 5.7 | 0.6% | Mar 5, 2023 | Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsiste... |
| CVE-2023-0734 | MEDIUM | 5.3 | 0.5% | Mar 5, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4. |
| CVE-2023-1181 | MEDIUM | 5.4 | 0.4% | Mar 5, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now