2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47217 | MEDIUM | 5.5 | 0.2% | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow. |
| CVE-2023-46705 | MEDIUM | 5.5 | 0.2% | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion. |
| CVE-2023-46100 | MEDIUM | 5.5 | 0.2% | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitia... |
| CVE-2023-42774 | MEDIUM | 5.5 | 0.2% | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default ... |
| CVE-2023-3379 | MEDIUM | 5.3 | 0.2% | Nov 20, 2023 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to chan... |
| CVE-2023-47175 | MEDIUM | 6.1 | 0.7% | Nov 20, 2023 | Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior ... |
| CVE-2023-5341 | MEDIUM | 5.5 | 0.4% | Nov 19, 2023 | A heap use-after-free flaw was found in coders/bmp.c in ImageMagick. |
| CVE-2023-48736 | MEDIUM | 6.5 | 0.6% | Nov 18, 2023 | In International Color Consortium DemoIccMAX 3e7948b, CIccCLUT::Interp2d in IccTagLut.cpp in libSampleICC.a has an out-o... |
| CVE-2023-40363 | MEDIUM | 6.5 | 0.6% | Nov 18, 2023 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect f... |
| CVE-2023-40817 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field. |
| CVE-2023-40816 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field. |
| CVE-2023-40815 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field. |
| CVE-2023-40814 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field. |
| CVE-2023-40813 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation. |
| CVE-2023-40812 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field. |
| CVE-2023-40810 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field. |
| CVE-2023-40809 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number. |
| CVE-2023-44796 | MEDIUM | 5.4 | 0.7% | Nov 18, 2023 | Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate ... |
| CVE-2023-48294 | MEDIUM | 4.3 | 0.7% | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo... |
| CVE-2023-48295 | MEDIUM | 5.4 | 0.6% | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo... |
| CVE-2023-48024 | MEDIUM | 6.5 | 0.6% | Nov 17, 2023 | Liblisp through commit 4c65969 was discovered to contain a use-after-free vulnerability in void hash_destroy(hash_table_... |
| CVE-2023-44355 | MEDIUM | 4.3 | 47.2% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vu... |
| CVE-2023-44352 | MEDIUM | 6.1 | 84.8% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scriptin... |
| CVE-2023-26364 | MEDIUM | 5.3 | 1.0% | Nov 17, 2023 | @adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result ... |
| CVE-2023-22268 | MEDIUM | 6.5 | 1.2% | Nov 17, 2023 | Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now