2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46058 | MEDIUM | 4.8 | 0.6% | Oct 24, 2023 | Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c... |
| CVE-2023-45998 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS. |
| CVE-2023-44760 | MEDIUM | 4.8 | 0.6% | Oct 23, 2023 | Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code ... |
| CVE-2023-43358 | MEDIUM | 5.4 | 0.5% | Oct 23, 2023 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra... |
| CVE-2023-37636 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitr... |
| CVE-2023-33840 | MEDIUM | 4.8 | 0.3% | Oct 23, 2023 | IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2023-27149 | MEDIUM | 4.8 | 0.4% | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary ... |
| CVE-2023-27148 | MEDIUM | 4.8 | 0.4% | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to... |
| CVE-2023-46288 | MEDIUM | 4.3 | 1.4% | Oct 23, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Air... |
| CVE-2023-38722 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulne... |
| CVE-2023-46331 | MEDIUM | 5.5 | 0.2% | Oct 23, 2023 | WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fa... |
| CVE-2023-37532 | MEDIUM | 4.3 | 0.5% | Oct 23, 2023 | HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files o... |
| CVE-2023-46332 | MEDIUM | 5.5 | 0.3% | Oct 23, 2023 | WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault. |
| CVE-2023-43067 | MEDIUM | 6.5 | 0.4% | Oct 23, 2023 | Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploi... |
| CVE-2023-5718 | MEDIUM | 4.3 | 0.2% | Oct 23, 2023 | The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessa... |
| CVE-2023-46127 | MEDIUM | 5.4 | 37.0% | Oct 23, 2023 | Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated clien... |
| CVE-2023-43065 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can expl... |
| CVE-2023-28804 | MEDIUM | 5.3 | 0.2% | Oct 23, 2023 | An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing ... |
| CVE-2023-28803 | MEDIUM | 6.5 | 0.3% | Oct 23, 2023 | An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on ... |
| CVE-2023-45802 | MEDIUM | 5.9 | 3.0% | Oct 23, 2023 | When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were... |
| CVE-2023-43624 | MEDIUM | 5.5 | 0.2% | Oct 23, 2023 | CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML externa... |
| CVE-2023-5702 | MEDIUM | 6.5 | 14.5% | Oct 23, 2023 | A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue ... |
| CVE-2023-5701 | MEDIUM | 6.1 | 0.7% | Oct 23, 2023 | A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerabilit... |
| CVE-2023-5699 | MEDIUM | 6.1 | 0.5% | Oct 23, 2023 | A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issu... |
| CVE-2023-5698 | MEDIUM | 6.1 | 0.5% | Oct 23, 2023 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now