2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36027 | MEDIUM | 6.3 | 1.1% | Nov 10, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-46735 | MEDIUM | 6.1 | 0.6% | Nov 10, 2023 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.... |
| CVE-2023-46734 | MEDIUM | 6.1 | 0.7% | Nov 10, 2023 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2... |
| CVE-2023-46733 | MEDIUM | 6.5 | 0.7% | Nov 10, 2023 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5... |
| CVE-2023-4949 | MEDIUM | 6.7 | 0.2% | Nov 10, 2023 | An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition... |
| CVE-2023-6075 | MEDIUM | 6.1 | 0.5% | Nov 10, 2023 | A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is ... |
| CVE-2023-47119 | MEDIUM | 6.1 | 0.9% | Nov 10, 2023 | Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version... |
| CVE-2023-46130 | MEDIUM | 5.4 | 0.7% | Nov 10, 2023 | Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version... |
| CVE-2023-45806 | MEDIUM | 5.4 | 1.0% | Nov 10, 2023 | Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version... |
| CVE-2023-47164 | MEDIUM | 6.1 | 0.7% | Nov 10, 2023 | Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute a... |
| CVE-2023-6073 | MEDIUM | 6.3 | 0.4% | Nov 10, 2023 | Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of ... |
| CVE-2023-45167 | MEDIUM | 5.5 | 0.3% | Nov 10, 2023 | IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial... |
| CVE-2023-46729 | MEDIUM | 6.1 | 0.6% | Nov 10, 2023 | sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sendin... |
| CVE-2023-5549 | MEDIUM | 5.3 | 0.6% | Nov 9, 2023 | Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a par... |
| CVE-2023-5548 | MEDIUM | 5.3 | 0.3% | Nov 9, 2023 | Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. |
| CVE-2023-5547 | MEDIUM | 6.1 | 0.5% | Nov 9, 2023 | The course upload preview contained an XSS risk for users uploading unsafe data. |
| CVE-2023-5546 | MEDIUM | 5.4 | 1.2% | Nov 9, 2023 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. |
| CVE-2023-5545 | MEDIUM | 5.3 | 0.5% | Nov 9, 2023 | H5P metadata automatically populated the author with the user's username, which could be sensitive information. |
| CVE-2023-5544 | MEDIUM | 5.4 | 0.5% | Nov 9, 2023 | Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR ris... |
| CVE-2023-5542 | MEDIUM | 4.3 | 0.4% | Nov 9, 2023 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. |
| CVE-2023-5541 | MEDIUM | 6.1 | 0.5% | Nov 9, 2023 | The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content. |
| CVE-2023-39198 | MEDIUM | 6.4 | 0.4% | Nov 9, 2023 | A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the q... |
| CVE-2023-45885 | MEDIUM | 5.4 | 0.4% | Nov 9, 2023 | Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary ... |
| CVE-2023-45884 | MEDIUM | 6.5 | 0.3% | Nov 9, 2023 | Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view se... |
| CVE-2023-45284 | MEDIUM | 5.3 | 0.9% | Nov 9, 2023 | On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now