2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38059 | MEDIUM | 5.3 | 0.5% | Oct 16, 2023 | The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the pay... |
| CVE-2023-21414 | MEDIUM | 6.8 | 0.2% | Oct 16, 2023 | NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection fo... |
| CVE-2023-40791 | MEDIUM | 6.3 | 0.4% | Oct 16, 2023 | extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, a... |
| CVE-2023-5591 | MEDIUM | 6.5 | 22.2% | Oct 16, 2023 | SQL Injection in GitHub repository librenms/librenms prior to 23.10.0. |
| CVE-2023-35013 | MEDIUM | 4.4 | 0.2% | Oct 16, 2023 | IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive informatio... |
| CVE-2023-5588 | MEDIUM | 5.3 | 0.6% | Oct 15, 2023 | A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emo... |
| CVE-2023-5585 | MEDIUM | 6.1 | 0.3% | Oct 15, 2023 | A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. Th... |
| CVE-2023-45863 | MEDIUM | 6.4 | 0.3% | Oct 14, 2023 | An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access, an attacker can trigger a r... |
| CVE-2023-45862 | MEDIUM | 5.5 | 0.3% | Oct 14, 2023 | An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before ... |
| CVE-2023-40367 | MEDIUM | 5.4 | 0.3% | Oct 14, 2023 | IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri... |
| CVE-2023-45176 | MEDIUM | 5.5 | 0.2% | Oct 14, 2023 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 1... |
| CVE-2023-5582 | MEDIUM | 5.4 | 0.5% | Oct 14, 2023 | A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown pr... |
| CVE-2023-5581 | MEDIUM | 6.1 | 0.5% | Oct 14, 2023 | A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability af... |
| CVE-2023-5579 | MEDIUM | 6.5 | 0.3% | Oct 14, 2023 | A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unkno... |
| CVE-2023-1259 | MEDIUM | 5.5 | 0.5% | Oct 14, 2023 | The Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hotjar_site_id in versions up to, a... |
| CVE-2023-5578 | MEDIUM | 5.4 | 0.3% | Oct 14, 2023 | A vulnerability was found in Portábilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vuln... |
| CVE-2023-45348 | MEDIUM | 4.3 | 1.2% | Oct 14, 2023 | Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve s... |
| CVE-2023-42792 | MEDIUM | 6.5 | 1.4% | Oct 14, 2023 | Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with lim... |
| CVE-2023-42780 | MEDIUM | 6.5 | 1.1% | Oct 14, 2023 | Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to... |
| CVE-2023-42663 | MEDIUM | 6.5 | 1.6% | Oct 14, 2023 | Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specifi... |
| CVE-2023-30148 | MEDIUM | 5.4 | 0.4% | Oct 14, 2023 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart ... |
| CVE-2023-45674 | MEDIUM | 6.5 | 0.5% | Oct 14, 2023 | Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was ... |
| CVE-2023-36559 | MEDIUM | 4.2 | 0.8% | Oct 13, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2023-34977 | MEDIUM | 5.4 | 0.3% | Oct 13, 2023 | A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability co... |
| CVE-2023-32970 | MEDIUM | 4.9 | 0.5% | Oct 13, 2023 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now