2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21719 | MEDIUM | 6.5 | 1.7% | Jan 24, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2023-22484 | HIGH | 7.5 | 1.0% | Jan 23, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29... |
| CVE-2023-22483 | HIGH | 7.5 | 0.9% | Jan 23, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29... |
| CVE-2023-22630 | MEDIUM | 4.3 | 0.6% | Jan 23, 2023 | IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI. |
| CVE-2023-23560 | CRITICAL | 9.8 | 15.0% | Jan 23, 2023 | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. |
| CVE-2023-22960 | HIGH | 7.5 | 27.8% | Jan 23, 2023 | Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. |
| CVE-2023-23824 | HIGH | 8.8 | 0.7% | Jan 23, 2023 | Auth. SQL Injection (SQLi) vulnerability in WP-TopBar <= 5.36 versions. |
| CVE-2023-23687 | MEDIUM | 5.4 | 0.4% | Jan 23, 2023 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions. |
| CVE-2023-22721 | MEDIUM | 5.4 | 0.4% | Jan 23, 2023 | Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions. |
| CVE-2023-0447 | MEDIUM | 4.3 | 0.6% | Jan 23, 2023 | The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t... |
| CVE-2023-0446 | MEDIUM | 5.5 | 0.6% | Jan 23, 2023 | The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in ... |
| CVE-2023-24099 | HIGH | 8.8 | 1.0% | Jan 23, 2023 | TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow... |
| CVE-2023-24098 | HIGH | 8.8 | 1.0% | Jan 23, 2023 | TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow... |
| CVE-2023-24097 | HIGH | 8.8 | 1.0% | Jan 23, 2023 | TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow... |
| CVE-2023-24096 | HIGH | 8.8 | 1.0% | Jan 23, 2023 | TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow... |
| CVE-2023-24095 | HIGH | 8.8 | 1.0% | Jan 23, 2023 | TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow... |
| CVE-2023-0440 | MEDIUM | 5.3 | 0.6% | Jan 23, 2023 | Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6. |
| CVE-2023-0438 | MEDIUM | 6.5 | 0.3% | Jan 23, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
| CVE-2023-24069 | LOW | 3.3 | 0.9% | Jan 23, 2023 | Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments ... |
| CVE-2023-24068 | HIGH | 7.8 | 0.4% | Jan 23, 2023 | Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within th... |
| CVE-2023-24070 | MEDIUM | 6.1 | 0.4% | Jan 23, 2023 | app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. |
| CVE-2023-23314 | HIGH | 8.8 | 1.2% | Jan 23, 2023 | An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary... |
| CVE-2023-0435 | CRITICAL | 9.8 | 0.7% | Jan 22, 2023 | Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41. |
| CVE-2023-24059 | HIGH | 7.3 | 1.5% | Jan 22, 2023 | Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploite... |
| CVE-2023-24058 | MEDIUM | 4.3 | 0.9% | Jan 22, 2023 | Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now