2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42183 | MEDIUM | 5.3 | 0.6% | Dec 15, 2023 | lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of i... |
| CVE-2023-36878 | MEDIUM | 4.3 | 0.9% | Dec 15, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2023-6134 | MEDIUM | 5.4 | 0.9% | Dec 14, 2023 | A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to t... |
| CVE-2023-0248 | MEDIUM | 5.3 | 0.3% | Dec 14, 2023 | An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certa... |
| CVE-2023-49786 | MEDIUM | 5.9 | 5.3% | Dec 14, 2023 | Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1,... |
| CVE-2023-50713 | MEDIUM | 5 | 0.4% | Dec 14, 2023 | Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A ... |
| CVE-2023-50710 | MEDIUM | 4.3 | 0.6% | Dec 14, 2023 | Hono is a web framework written in TypeScript. Prior to version 3.11.7, clients may override named path parameter values... |
| CVE-2023-49157 | MEDIUM | 4.8 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andreas Münch Mult... |
| CVE-2023-49152 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labs64 Credit Trac... |
| CVE-2023-49151 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Calendar Si... |
| CVE-2023-5769 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious act... |
| CVE-2023-49860 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project ... |
| CVE-2023-49842 | MEDIUM | 4.8 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket... |
| CVE-2023-49150 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today... |
| CVE-2023-49149 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today... |
| CVE-2023-48780 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnigmaWeb WP Catal... |
| CVE-2023-48771 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno "Aesqe" Babi... |
| CVE-2023-48770 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nima Saberi Aparat... |
| CVE-2023-48767 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raghu Goriya MyTub... |
| CVE-2023-48756 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBloc... |
| CVE-2023-6595 | MEDIUM | 5.3 | 0.8% | Dec 14, 2023 | In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It... |
| CVE-2023-6368 | MEDIUM | 5.3 | 0.6% | Dec 14, 2023 | In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It... |
| CVE-2023-6367 | MEDIUM | 5.4 | 0.5% | Dec 14, 2023 | In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.... |
| CVE-2023-6366 | MEDIUM | 5.4 | 0.5% | Dec 14, 2023 | In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.... |
| CVE-2023-6365 | MEDIUM | 5.4 | 0.5% | Dec 14, 2023 | In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now