2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6303 | MEDIUM | 4.8 | 0.6% | Nov 27, 2023 | A vulnerability was found in CSZCMS 1.3.0. It has been classified as problematic. This affects an unknown part of the fi... |
| CVE-2023-6301 | MEDIUM | 6.1 | 0.6% | Nov 27, 2023 | A vulnerability has been found in SourceCodester Best Courier Management System 1.0 and classified as problematic. Affec... |
| CVE-2023-6300 | MEDIUM | 6.1 | 0.6% | Nov 27, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Best Courier Management System 1.0. Af... |
| CVE-2023-49321 | MEDIUM | 5.3 | 0.6% | Nov 27, 2023 | Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the ... |
| CVE-2023-6299 | MEDIUM | 6.5 | 0.9% | Nov 26, 2023 | A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unkn... |
| CVE-2023-6298 | MEDIUM | 6.5 | 1.1% | Nov 26, 2023 | A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main ... |
| CVE-2023-6297 | MEDIUM | 6.1 | 0.8% | Nov 26, 2023 | A vulnerability classified as problematic has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This a... |
| CVE-2023-6296 | MEDIUM | 6.1 | 0.8% | Nov 26, 2023 | A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown func... |
| CVE-2023-6277 | MEDIUM | 6.5 | 1.8% | Nov 24, 2023 | An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to... |
| CVE-2023-48708 | MEDIUM | 6.5 | 0.6% | Nov 24, 2023 | CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful lo... |
| CVE-2023-48707 | MEDIUM | 6.5 | 0.3% | Nov 24, 2023 | CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an import... |
| CVE-2023-6275 | MEDIUM | 6.1 | 2.4% | Nov 24, 2023 | A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by... |
| CVE-2023-33706 | MEDIUM | 6.5 | 0.6% | Nov 24, 2023 | SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter t... |
| CVE-2023-49216 | MEDIUM | 5.4 | 0.4% | Nov 23, 2023 | Usedesk before 1.7.57 allows profile stored XSS. |
| CVE-2023-49215 | MEDIUM | 6.1 | 0.4% | Nov 23, 2023 | Usedesk before 1.7.57 allows filter reflected XSS. |
| CVE-2023-33202 | MEDIUM | 5.5 | 0.9% | Nov 23, 2023 | Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bounc... |
| CVE-2023-41811 | MEDIUM | 6.1 | 0.3% | Nov 23, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all... |
| CVE-2023-41810 | MEDIUM | 6.1 | 0.3% | Nov 23, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all... |
| CVE-2023-41792 | MEDIUM | 6.1 | 0.2% | Nov 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerabil... |
| CVE-2023-41791 | MEDIUM | 5.4 | 0.5% | Nov 23, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all... |
| CVE-2023-41789 | MEDIUM | 6.1 | 0.5% | Nov 23, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all... |
| CVE-2023-41786 | MEDIUM | 6.5 | 0.5% | Nov 23, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. Th... |
| CVE-2023-4595 | MEDIUM | 6.5 | 0.7% | Nov 23, 2023 | An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve se... |
| CVE-2023-4594 | MEDIUM | 5.4 | 0.4% | Nov 23, 2023 | Stored XSS vulnerability. This vulnerability could allow an attacker to store a malicious JavaScript payload via GET and... |
| CVE-2023-4593 | MEDIUM | 6.5 | 1.1% | Nov 23, 2023 | Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's int... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now