2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23143 | HIGH | 7.8 | 0.4% | Jan 20, 2023 | Buffer overflow vulnerability in function avc_parse_slice in file media_tools/av_parsers.c. GPAC version 2.3-DEV-rev1-g4... |
| CVE-2023-23024 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index... |
| CVE-2023-23015 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in Kalkun 0.8.0 via username input in file User_model.php. |
| CVE-2023-23014 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr... |
| CVE-2023-23012 | MEDIUM | 6.1 | 0.5% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary co... |
| CVE-2023-23010 | MEDIUM | 6.1 | 0.6% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c... |
| CVE-2023-22458 | MEDIUM | 5.5 | 69.4% | Jan 20, 2023 | Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` comm... |
| CVE-2023-0101 | HIGH | 8.8 | 0.8% | Jan 20, 2023 | A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. ... |
| CVE-2023-23489 | CRITICAL | 9.8 | 11.2% | Jan 20, 2023 | The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection... |
| CVE-2023-23488 | CRITICAL | 9.8 | 92.5% | Jan 20, 2023 | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit... |
| CVE-2023-22912 | MEDIUM | 5.3 | 0.4% | Jan 20, 2023 | An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. Check... |
| CVE-2023-22910 | MEDIUM | 5.4 | 0.5% | Jan 20, 2023 | An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There... |
| CVE-2023-22964 | CRITICAL | 9.1 | 2.4% | Jan 20, 2023 | Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when L... |
| CVE-2023-23691 | HIGH | 8.8 | 0.4% | Jan 20, 2023 | Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated ... |
| CVE-2023-23596 | HIGH | 8.8 | 15.2% | Jan 20, 2023 | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an... |
| CVE-2023-20058 | MEDIUM | 6.1 | 0.5% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate... |
| CVE-2023-20057 | MEDIUM | 5.3 | 0.7% | Jan 20, 2023 | A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could ... |
| CVE-2023-20047 | MEDIUM | 6.5 | 0.3% | Jan 20, 2023 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devi... |
| CVE-2023-20045 | HIGH | 7.2 | 1.0% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could a... |
| CVE-2023-20044 | HIGH | 7.3 | 0.1% | Jan 20, 2023 | A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. ... |
| CVE-2023-20043 | MEDIUM | 6.7 | 0.2% | Jan 20, 2023 | A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. ... |
| CVE-2023-20040 | MEDIUM | 5.5 | 1.2% | Jan 20, 2023 | A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote... |
| CVE-2023-20038 | HIGH | 8.8 | 0.2% | Jan 20, 2023 | A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local a... |
| CVE-2023-20037 | MEDIUM | 5.4 | 0.4% | Jan 20, 2023 | A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cro... |
| CVE-2023-20026 | HIGH | 7.2 | 1.3% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV3... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now