2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0949 | MEDIUM | 4.8 | 0.5% | Feb 22, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5. |
| CVE-2023-26314 | HIGH | 8.8 | 1.0% | Feb 22, 2023 | The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-e... |
| CVE-2023-24108 | CRITICAL | 9.8 | 1.4% | Feb 22, 2023 | MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request pa... |
| CVE-2023-24107 | CRITICAL | 9.8 | 1.2% | Feb 22, 2023 | hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution back... |
| CVE-2023-0947 | CRITICAL | 9.8 | 3.6% | Feb 22, 2023 | Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3. |
| CVE-2023-20858 | HIGH | 7.2 | 16.9% | Feb 22, 2023 | VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injectio... |
| CVE-2023-20855 | HIGH | 8.8 | 1.3% | Feb 22, 2023 | VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administra... |
| CVE-2023-24081 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in Redrock Software TutorTrac before v4.2.170210 allows attac... |
| CVE-2023-24080 | CRITICAL | 9.8 | 1.1% | Feb 21, 2023 | A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to co... |
| CVE-2023-25157 | CRITICAL | 9.8 | 85.2% | Feb 21, 2023 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServ... |
| CVE-2023-24320 | CRITICAL | 9.8 | 1.3% | Feb 21, 2023 | An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via u... |
| CVE-2023-25812 | HIGH | 8.8 | 1.0% | Feb 21, 2023 | Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGover... |
| CVE-2023-25811 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a pers... |
| CVE-2023-25810 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persisten... |
| CVE-2023-25657 | CRITICAL | 9.8 | 1.5% | Feb 21, 2023 | Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions earlier than 1.5.7... |
| CVE-2023-25158 | CRITICAL | 9.8 | 1.1% | Feb 21, 2023 | GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filte... |
| CVE-2023-0946 | CRITICAL | 9.8 | 0.5% | Feb 21, 2023 | A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by ... |
| CVE-2023-0945 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0. Affect... |
| CVE-2023-0943 | HIGH | 8.8 | 2.3% | Feb 21, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. T... |
| CVE-2023-0942 | MEDIUM | 6.1 | 1.2% | Feb 21, 2023 | The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ paramet... |
| CVE-2023-23009 | MEDIUM | 6.5 | 1.6% | Feb 21, 2023 | Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS pa... |
| CVE-2023-22984 | MEDIUM | 6.1 | 0.5% | Feb 21, 2023 | A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administra... |
| CVE-2023-22920 | CRITICAL | 9.8 | 0.8% | Feb 21, 2023 | A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a fac... |
| CVE-2023-24184 | CRITICAL | 9.8 | 1.3% | Feb 21, 2023 | TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability. |
| CVE-2023-0934 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.5. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now