2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52263 | MEDIUM | 6.1 | 0.5% | Dec 30, 2023 | Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to br... |
| CVE-2023-7180 | MEDIUM | 4.3 | 0.5% | Dec 30, 2023 | A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability i... |
| CVE-2023-50550 | MEDIUM | 5.4 | 0.3% | Dec 30, 2023 | layui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter. |
| CVE-2023-7173 | MEDIUM | 5.4 | 1.5% | Dec 30, 2023 | A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affec... |
| CVE-2023-52257 | MEDIUM | 6.1 | 0.4% | Dec 30, 2023 | LogoBee 0.2 allows updates.php?id= XSS. |
| CVE-2023-38023 | MEDIUM | 5.5 | 0.2% | Dec 30, 2023 | An issue was discovered in SCONE Confidential Computing Platform before 5.8.0 for Intel SGX. Lack of pointer-alignment l... |
| CVE-2023-38022 | MEDIUM | 5.5 | 0.2% | Dec 30, 2023 | An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.29 for Intel SGX. I... |
| CVE-2023-38021 | MEDIUM | 5.5 | 0.2% | Dec 30, 2023 | An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. L... |
| CVE-2023-50559 | MEDIUM | 5.5 | 0.2% | Dec 30, 2023 | An issue was discovered in XiangShan v2.1, allows local attackers to obtain sensitive information via the L1D cache. |
| CVE-2023-52240 | MEDIUM | 6.1 | 0.5% | Dec 29, 2023 | The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Bindi... |
| CVE-2023-50069 | MEDIUM | 6.1 | 0.4% | Dec 29, 2023 | WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the reco... |
| CVE-2023-7171 | MEDIUM | 4.8 | 0.5% | Dec 29, 2023 | A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability... |
| CVE-2023-51663 | MEDIUM | 5.3 | 0.4% | Dec 29, 2023 | Hail is an open-source, general-purpose, Python-based data analysis tool with additional data types and methods for work... |
| CVE-2023-51517 | MEDIUM | 5.4 | 0.3% | Dec 29, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affect... |
| CVE-2023-50572 | MEDIUM | 5.5 | 0.3% | Dec 29, 2023 | An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to cause an OOM (OutofMemory) er... |
| CVE-2023-50570 | MEDIUM | 5.5 | 0.3% | Dec 29, 2023 | An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because ... |
| CVE-2023-51675 | MEDIUM | 5.4 | 0.3% | Dec 29, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, U... |
| CVE-2023-7113 | MEDIUM | 6.1 | 0.3% | Dec 29, 2023 | Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject... |
| CVE-2023-51676 | MEDIUM | 6.5 | 0.3% | Dec 29, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons fo... |
| CVE-2023-7079 | MEDIUM | 5.7 | 0.7% | Dec 29, 2023 | Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the ... |
| CVE-2023-50893 | MEDIUM | 6.1 | 0.4% | Dec 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution Impreza... |
| CVE-2023-50892 | MEDIUM | 6.1 | 0.3% | Dec 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2023-50891 | MEDIUM | 5.4 | 1.1% | Dec 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form pl... |
| CVE-2023-50889 | MEDIUM | 5.4 | 0.3% | Dec 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder... |
| CVE-2023-50881 | MEDIUM | 5.4 | 0.3% | Dec 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Acces... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now