2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29046 | MEDIUM | 4.3 | 0.5% | Nov 2, 2023 | Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, ins... |
| CVE-2023-29045 | MEDIUM | 5.4 | 0.4% | Nov 2, 2023 | Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. ... |
| CVE-2023-29044 | MEDIUM | 5.4 | 0.4% | Nov 2, 2023 | Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be inje... |
| CVE-2023-29043 | MEDIUM | 6.1 | 0.3% | Nov 2, 2023 | Presentations may contain references to images, which are user-controlled, and could include malicious script code that ... |
| CVE-2023-26456 | MEDIUM | 5.4 | 0.4% | Nov 2, 2023 | Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before ... |
| CVE-2023-46475 | MEDIUM | 5.4 | 0.4% | Nov 2, 2023 | A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the ... |
| CVE-2023-43193 | MEDIUM | 6.1 | 0.5% | Nov 2, 2023 | Submitty before v22.06.00 is vulnerable to Cross Site Scripting (XSS). An attacker can create a malicious link in the fo... |
| CVE-2023-3164 | MEDIUM | 5.5 | 0.3% | Nov 2, 2023 | A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/t... |
| CVE-2023-5917 | MEDIUM | 6.1 | 0.5% | Nov 2, 2023 | A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the funct... |
| CVE-2023-5916 | MEDIUM | 4.3 | 0.5% | Nov 2, 2023 | A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /... |
| CVE-2023-43087 | MEDIUM | 6.5 | 0.4% | Nov 2, 2023 | Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privilege... |
| CVE-2023-43076 | MEDIUM | 6.5 | 0.6% | Nov 2, 2023 | Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker... |
| CVE-2023-5876 | MEDIUM | 5.3 | 0.5% | Nov 2, 2023 | Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro... |
| CVE-2023-5875 | MEDIUM | 5.3 | 0.3% | Nov 2, 2023 | Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi... |
| CVE-2023-5606 | MEDIUM | 4.8 | 0.3% | Nov 2, 2023 | The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9... |
| CVE-2023-46595 | MEDIUM | 5.4 | 0.3% | Nov 2, 2023 | Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain cre... |
| CVE-2023-46327 | MEDIUM | 5.9 | 0.4% | Nov 2, 2023 | Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a fa... |
| CVE-2023-5910 | MEDIUM | 6.1 | 0.4% | Nov 2, 2023 | A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing o... |
| CVE-2023-45203 | MEDIUM | 6.1 | 0.4% | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.p... |
| CVE-2023-45202 | MEDIUM | 6.1 | 0.4% | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.ph... |
| CVE-2023-44954 | MEDIUM | 5.4 | 0.6% | Nov 1, 2023 | Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID ... |
| CVE-2023-46448 | MEDIUM | 6.1 | 0.4% | Nov 1, 2023 | Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to ... |
| CVE-2023-45201 | MEDIUM | 6.1 | 0.4% | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.p... |
| CVE-2023-3397 | MEDIUM | 6.3 | 0.2% | Nov 1, 2023 | A race condition occurred between the functions lmLogClose and txEnd in JFS, in the Linux Kernel, executed in different ... |
| CVE-2023-1193 | MEDIUM | 6.5 | 1.0% | Nov 1, 2023 | A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now