2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48825 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Cod... |
| CVE-2023-48824 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or key... |
| CVE-2023-48208 | MEDIUM | 6.1 | 0.5% | Dec 7, 2023 | A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via th... |
| CVE-2023-48206 | MEDIUM | 6.1 | 0.6% | Dec 7, 2023 | A Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to injec... |
| CVE-2023-48205 | MEDIUM | 5.3 | 0.8% | Dec 7, 2023 | Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emai... |
| CVE-2023-43299 | MEDIUM | 5.3 | 0.5% | Dec 7, 2023 | An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of... |
| CVE-2023-43298 | MEDIUM | 5.3 | 0.5% | Dec 7, 2023 | An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leak... |
| CVE-2023-48172 | MEDIUM | 5.4 | 0.7% | Dec 7, 2023 | A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript... |
| CVE-2023-46916 | MEDIUM | 4.3 | 0.5% | Dec 7, 2023 | Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to... |
| CVE-2023-46857 | MEDIUM | 5.4 | 0.6% | Dec 7, 2023 | Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomp... |
| CVE-2023-43103 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. ... |
| CVE-2023-43102 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox... |
| CVE-2023-6568 | MEDIUM | 6.1 | 1.6% | Dec 7, 2023 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the han... |
| CVE-2023-28017 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi... |
| CVE-2023-40238 | MEDIUM | 5.5 | 1.9% | Dec 7, 2023 | A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.4... |
| CVE-2023-5714 | MEDIUM | 4.3 | 0.4% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5713 | MEDIUM | 4.3 | 0.5% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5712 | MEDIUM | 4.3 | 0.4% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5711 | MEDIUM | 4.3 | 0.4% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5710 | MEDIUM | 4.3 | 0.5% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-46218 | MEDIUM | 6.5 | 1.7% | Dec 7, 2023 | This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than w... |
| CVE-2023-6566 | MEDIUM | 6.5 | 0.5% | Dec 7, 2023 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-6393 | MEDIUM | 5.3 | 0.6% | Dec 6, 2023 | A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the ... |
| CVE-2023-39326 | MEDIUM | 5.3 | 1.2% | Dec 6, 2023 | A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read man... |
| CVE-2023-6459 | MEDIUM | 5.3 | 0.5% | Dec 6, 2023 | Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the ch... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now