2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7143 | MEDIUM | 4.8 | 0.5% | Dec 29, 2023 | A vulnerability was found in code-projects Client Details System 1.0. It has been rated as problematic. Affected by this... |
| CVE-2023-52085 | MEDIUM | 5.4 | 30.2% | Dec 29, 2023 | Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker F... |
| CVE-2023-52084 | MEDIUM | 5.4 | 0.3% | Dec 28, 2023 | Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include... |
| CVE-2023-52083 | MEDIUM | 4.8 | 0.3% | Dec 28, 2023 | Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission... |
| CVE-2023-50448 | MEDIUM | 6.5 | 0.5% | Dec 28, 2023 | In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially priv... |
| CVE-2023-7136 | MEDIUM | 5.4 | 0.5% | Dec 28, 2023 | A vulnerability classified as problematic was found in code-projects Record Management System 1.0. Affected by this vuln... |
| CVE-2023-7135 | MEDIUM | 5.4 | 0.5% | Dec 28, 2023 | A vulnerability classified as problematic has been found in code-projects Record Management System 1.0. Affected is an u... |
| CVE-2023-7133 | MEDIUM | 6.1 | 0.7% | Dec 28, 2023 | A vulnerability was found in y_project RuoYi 4.7.8. It has been declared as problematic. This vulnerability affects unkn... |
| CVE-2023-7132 | MEDIUM | 5.4 | 0.6% | Dec 28, 2023 | A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problemati... |
| CVE-2023-52081 | MEDIUM | 5.3 | 0.5% | Dec 28, 2023 | ffcss is a CLI interface to apply and configure Firefox CSS themes. Prior to 0.2.0, the function `lookupPreprocess()` is... |
| CVE-2023-52079 | MEDIUM | 6.5 | 0.7% | Dec 28, 2023 | msgpackr is a fast MessagePack NodeJS/JavaScript implementation. Prior to 1.10.1, when decoding user supplied MessagePac... |
| CVE-2023-50267 | MEDIUM | 4.3 | 0.3% | Dec 28, 2023 | MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can... |
| CVE-2023-50470 | MEDIUM | 5.4 | 0.5% | Dec 28, 2023 | A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute... |
| CVE-2023-50860 | MEDIUM | 5.4 | 0.3% | Dec 28, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TMS Booking for Ap... |
| CVE-2023-50859 | MEDIUM | 5.4 | 0.3% | Dec 28, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfu... |
| CVE-2023-50836 | MEDIUM | 4.8 | 0.3% | Dec 28, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ibericode HTML For... |
| CVE-2023-51501 | MEDIUM | 6.1 | 0.4% | Dec 28, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Cr... |
| CVE-2023-50874 | MEDIUM | 5.4 | 0.3% | Dec 28, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Word... |
| CVE-2023-4672 | MEDIUM | 6.1 | 0.3% | Dec 28, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software EC... |
| CVE-2023-45702 | MEDIUM | 5.5 | 0.2% | Dec 28, 2023 | An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of ... |
| CVE-2023-45701 | MEDIUM | 6.5 | 0.5% | Dec 28, 2023 | HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is retu... |
| CVE-2023-49469 | MEDIUM | 6.1 | 0.5% | Dec 28, 2023 | Reflected Cross Site Scripting (XSS) vulnerability in Shaarli v0.12.2, allows remote attackers to execute arbitrary code... |
| CVE-2023-51010 | MEDIUM | 5.3 | 0.4% | Dec 28, 2023 | An issue in the export component AdSdkH5Activity of com.sdjictec.qdmetro v4.2.2 allows attackers to open a crafted URL w... |
| CVE-2023-49229 | MEDIUM | 4.3 | 0.5% | Dec 28, 2023 | An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web ser... |
| CVE-2023-49228 | MEDIUM | 6.4 | 0.5% | Dec 28, 2023 | An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, wh... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now