2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52194 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takayuki Miyauchi ... |
| CVE-2023-52193 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team... |
| CVE-2023-52192 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official... |
| CVE-2023-52191 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Torbjon Infogram –... |
| CVE-2023-52189 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal In... |
| CVE-2023-52188 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson F... |
| CVE-2023-52175 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miuno... |
| CVE-2023-37621 | — | — | — | Feb 1, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-51939 | HIGH | 8.8 | 0.9% | Feb 1, 2024 | An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker... |
| CVE-2023-7069 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'... |
| CVE-2023-28807 | HIGH | 7.5 | 0.3% | Jan 31, 2024 | In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables... |
| CVE-2023-5390 | MEDIUM | 5.3 | 0.6% | Jan 31, 2024 | An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion Contro... |
| CVE-2023-50166 | MEDIUM | 6.1 | 0.3% | Jan 31, 2024 | Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. |
| CVE-2023-50165 | HIGH | 8.6 | 0.3% | Jan 31, 2024 | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. |
| CVE-2023-47116 | MEDIUM | 5.3 | 0.7% | Jan 31, 2024 | Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior t... |
| CVE-2023-6780 | MEDIUM | 5.3 | 2.7% | Jan 31, 2024 | An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the sy... |
| CVE-2023-6779 | HIGH | 7.5 | 3.1% | Jan 31, 2024 | An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This functio... |
| CVE-2023-6246 | HIGH | 7.8 | 4.8% | Jan 31, 2024 | A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called ... |
| CVE-2023-5992 | MEDIUM | 5.9 | 1.2% | Jan 31, 2024 | A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant... |
| CVE-2023-7043 | MEDIUM | 5.5 | 0.3% | Jan 31, 2024 | Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with t... |
| CVE-2023-50357 | MEDIUM | 5.4 | 0.4% | Jan 31, 2024 | A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gai... |
| CVE-2023-50356 | MEDIUM | 6.5 | 0.3% | Jan 31, 2024 | SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation... |
| CVE-2023-44313 | HIGH | 7.5 | 3.5% | Jan 31, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive se... |
| CVE-2023-44312 | HIGH | 7.5 | 0.8% | Jan 31, 2024 | Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apa... |
| CVE-2023-3934 | — | — | — | Jan 31, 2024 | Rejected reason: Please discard this CVE, we are not using this anymore. The vulnerability turned out to be a non-securi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now