2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45394 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 ... |
| CVE-2023-46115 | MEDIUM | 5.5 | 0.2% | Oct 20, 2023 | Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerabil... |
| CVE-2023-41894 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook compone... |
| CVE-2023-41893 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `clien... |
| CVE-2023-39731 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send ... |
| CVE-2023-43340 | MEDIUM | 5.2 | 0.5% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a cr... |
| CVE-2023-45819 | MEDIUM | 6.1 | 0.6% | Oct 19, 2023 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notif... |
| CVE-2023-45818 | MEDIUM | 6.1 | 0.6% | Oct 19, 2023 | TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyM... |
| CVE-2023-45815 | MEDIUM | 5.4 | 0.4% | Oct 19, 2023 | ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the... |
| CVE-2023-45280 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up... |
| CVE-2023-45279 | MEDIUM | 5.4 | 0.4% | Oct 19, 2023 | Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up... |
| CVE-2023-43875 | MEDIUM | 6.1 | 0.8% | Oct 19, 2023 | Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to ex... |
| CVE-2023-43359 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra... |
| CVE-2023-43344 | MEDIUM | 5.4 | 0.6% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co... |
| CVE-2023-43342 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co... |
| CVE-2023-43341 | MEDIUM | 6.1 | 0.6% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via ... |
| CVE-2023-45822 | MEDIUM | 5.3 | 0.5% | Oct 19, 2023 | Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for... |
| CVE-2023-45821 | MEDIUM | 6.3 | 0.2% | Oct 19, 2023 | Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for... |
| CVE-2023-30633 | MEDIUM | 5.3 | 0.2% | Oct 19, 2023 | An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR... |
| CVE-2023-45826 | MEDIUM | 6.5 | 1.9% | Oct 19, 2023 | Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.... |
| CVE-2023-45825 | MEDIUM | 5.5 | 0.2% | Oct 19, 2023 | ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custo... |
| CVE-2023-45820 | MEDIUM | 6.5 | 0.7% | Oct 19, 2023 | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus insta... |
| CVE-2023-42666 | MEDIUM | 5.3 | 0.4% | Oct 19, 2023 | The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnera... |
| CVE-2023-41088 | MEDIUM | 6.5 | 0.2% | Oct 19, 2023 | The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which ... |
| CVE-2023-40153 | MEDIUM | 6.1 | 0.3% | Oct 19, 2023 | The affected product is vulnerable to a cross-site scripting vulnerability, which could allow an attacker to access the... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now