2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50136 | MEDIUM | 5.4 | 0.4% | Jan 9, 2024 | Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field wh... |
| CVE-2023-38827 | MEDIUM | 6.1 | 0.4% | Jan 9, 2024 | Cross Site Scripting vulnerability in Follet School Solutions Destiny v.20_0_1_AU4 and later allows a remote attacker to... |
| CVE-2023-6129 | MEDIUM | 6.5 | 2.3% | Jan 9, 2024 | Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the inter... |
| CVE-2023-7223 | MEDIUM | 6.5 | 0.6% | Jan 9, 2024 | A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown ... |
| CVE-2023-51744 | MEDIUM | 5.5 | 0.2% | Jan 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < ... |
| CVE-2023-49722 | MEDIUM | 6.5 | 0.4% | Jan 9, 2024 | Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the devic... |
| CVE-2023-6149 | MEDIUM | 6.5 | 0.5% | Jan 9, 2024 | Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, w... |
| CVE-2023-6148 | MEDIUM | 5.4 | 0.5% | Jan 9, 2024 | Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a secu... |
| CVE-2023-50974 | MEDIUM | 5.5 | 0.3% | Jan 9, 2024 | In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appw... |
| CVE-2023-6147 | MEDIUM | 6.5 | 0.5% | Jan 9, 2024 | Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a secu... |
| CVE-2023-6842 | MEDIUM | 4.8 | 0.3% | Jan 9, 2024 | The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress i... |
| CVE-2023-6830 | MEDIUM | 6.1 | 0.4% | Jan 9, 2024 | The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vu... |
| CVE-2023-50932 | MEDIUM | 5.4 | 0.2% | Jan 9, 2024 | An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, th... |
| CVE-2023-50931 | MEDIUM | 5.4 | 0.2% | Jan 9, 2024 | An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the... |
| CVE-2023-6788 | MEDIUM | 5.4 | 0.2% | Jan 9, 2024 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2023-6594 | MEDIUM | 4.8 | 0.3% | Jan 9, 2024 | The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti... |
| CVE-2023-36629 | MEDIUM | 5.5 | 0.4% | Jan 9, 2024 | The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read. |
| CVE-2023-27000 | MEDIUM | 6.1 | 0.7% | Jan 9, 2024 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-26998 | MEDIUM | 5.4 | 0.7% | Jan 9, 2024 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-46906 | MEDIUM | 4.9 | 0.7% | Jan 9, 2024 | juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status cod... |
| CVE-2023-52198 | MEDIUM | 5.4 | 0.3% | Jan 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd P... |
| CVE-2023-52197 | MEDIUM | 4.8 | 0.3% | Jan 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads In... |
| CVE-2023-52196 | MEDIUM | 6.1 | 0.3% | Jan 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Boo... |
| CVE-2023-27739 | MEDIUM | 6.1 | 0.3% | Jan 8, 2024 | easyXDM 2.5 allows XSS via the xdm_e parameter. |
| CVE-2023-52271 | MEDIUM | 6.5 | 0.3% | Jan 8, 2024 | The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now