2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-52194MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takayuki Miyauchi ...
CVE-2023-52193MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team...
CVE-2023-52192MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official...
CVE-2023-52191MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Torbjon Infogram –...
CVE-2023-52189MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal In...
CVE-2023-52188MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson F...
CVE-2023-52175MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miuno...
CVE-2023-37621Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-51939HIGH8.8An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker...
CVE-2023-7069MEDIUM5.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'...
CVE-2023-28807HIGH7.5In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables...
CVE-2023-5390MEDIUM5.3An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion Contro...
CVE-2023-50166MEDIUM6.1Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2023-50165HIGH8.6Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
CVE-2023-47116MEDIUM5.3Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior t...
CVE-2023-6780MEDIUM5.3An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the sy...
CVE-2023-6779HIGH7.5An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This functio...
CVE-2023-6246HIGH7.8A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called ...
CVE-2023-5992MEDIUM5.9A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant...
CVE-2023-7043MEDIUM5.5Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with t...
CVE-2023-50357MEDIUM5.4A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gai...
CVE-2023-50356MEDIUM6.5SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation...
CVE-2023-44313HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive se...
CVE-2023-44312HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apa...
CVE-2023-3934Rejected reason: Please discard this CVE, we are not using this anymore. The vulnerability turned out to be a non-securi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now