2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47215 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prio... |
| CVE-2023-46711 | MEDIUM | 4.6 | 0.2% | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the p... |
| CVE-2023-46699 | MEDIUM | 4.3 | 0.2% | Dec 26, 2023 | Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0... |
| CVE-2023-45741 | MEDIUM | 6.8 | 0.3% | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute a... |
| CVE-2023-45740 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If th... |
| CVE-2023-45737 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin... |
| CVE-2023-42436 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this ... |
| CVE-2023-51654 | MEDIUM | 5.5 | 0.2% | Dec 26, 2023 | Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions ... |
| CVE-2023-50297 | MEDIUM | 6.1 | 0.4% | Dec 26, 2023 | Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to r... |
| CVE-2023-49117 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | PowerCMS (6 Series, 5 Series, and 4 Series) contains a stored cross-site scripting vulnerability. If this vulnerability ... |
| CVE-2023-27150 | MEDIUM | 5.4 | 0.4% | Dec 26, 2023 | openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of ... |
| CVE-2023-49944 | MEDIUM | 6.7 | 0.2% | Dec 25, 2023 | The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local adm... |
| CVE-2023-48652 | MEDIUM | 4.3 | 0.2% | Dec 25, 2023 | Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/s... |
| CVE-2023-38826 | MEDIUM | 6.1 | 0.4% | Dec 25, 2023 | A Cross Site Scripting (XSS) vulnerability exists in Follet Learning Solutions Destiny through 20.0_1U. via the handlewp... |
| CVE-2023-47247 | MEDIUM | 4.3 | 0.3% | Dec 25, 2023 | In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base artic... |
| CVE-2023-31297 | MEDIUM | 4.8 | 0.3% | Dec 25, 2023 | An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Na... |
| CVE-2023-40236 | MEDIUM | 5.3 | 0.4% | Dec 25, 2023 | In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, whic... |
| CVE-2023-37225 | MEDIUM | 6.1 | 0.3% | Dec 25, 2023 | Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links. |
| CVE-2023-30451 | MEDIUM | 4.9 | 1.2% | Dec 25, 2023 | In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary... |
| CVE-2023-7098 | MEDIUM | 5.3 | 0.7% | Dec 25, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret EasyImages 2.8.3. This vuln... |
| CVE-2023-7092 | MEDIUM | 4.3 | 0.4% | Dec 24, 2023 | A vulnerability was found in Uniway UW-302VP 2.0. It has been rated as problematic. This issue affects some unknown proc... |
| CVE-2023-51766 | MEDIUM | 5.3 | 1.1% | Dec 24, 2023 | Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a publi... |
| CVE-2023-51765 | MEDIUM | 5.3 | 1.1% | Dec 24, 2023 | sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitati... |
| CVE-2023-51764 | MEDIUM | 5.3 | 2.6% | Dec 24, 2023 | Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and ... |
| CVE-2023-49594 | MEDIUM | 6.5 | 1.2% | Dec 23, 2023 | An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthentica... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now