2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42640 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42639 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42638 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42637 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42636 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42635 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42634 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42633 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42632 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-42631 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with n... |
| CVE-2023-1715 | MEDIUM | 5.4 | 0.6% | Nov 1, 2023 | A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass... |
| CVE-2023-4198 | MEDIUM | 6.5 | 0.6% | Nov 1, 2023 | Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database tabl... |
| CVE-2023-5516 | MEDIUM | 5.3 | 0.4% | Nov 1, 2023 | Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, d... |
| CVE-2023-5515 | MEDIUM | 5.3 | 0.4% | Nov 1, 2023 | The responses for web queries with certain parameters disclose internal path of resources. This information can be used... |
| CVE-2023-5514 | MEDIUM | 5.3 | 0.4% | Nov 1, 2023 | The response messages received from the eSOMS report generation using certain parameter queries with full file path can... |
| CVE-2023-2622 | MEDIUM | 4.3 | 0.4% | Nov 1, 2023 | Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the... |
| CVE-2023-2621 | MEDIUM | 6.5 | 0.5% | Nov 1, 2023 | The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on th... |
| CVE-2023-5896 | MEDIUM | 5.4 | 0.3% | Nov 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.4.0-4. |
| CVE-2023-5895 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5894 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16. |
| CVE-2023-5892 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5891 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5890 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-47099 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the Create Virtual Server in Virtualmin 7.7 allows remote attackers... |
| CVE-2023-47098 | MEDIUM | 4.8 | 0.5% | Nov 1, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now