2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45322 | MEDIUM | 6.5 | 0.8% | Oct 6, 2023 | libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in ... |
| CVE-2023-5452 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2. |
| CVE-2023-21291 | MEDIUM | 5.5 | 0.1% | Oct 6, 2023 | In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing p... |
| CVE-2023-21253 | MEDIUM | 5.5 | 0.1% | Oct 6, 2023 | In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could ... |
| CVE-2023-21252 | MEDIUM | 5.5 | 0.1% | Oct 6, 2023 | In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to imp... |
| CVE-2023-21244 | MEDIUM | 6.7 | 0.1% | Oct 6, 2023 | In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission che... |
| CVE-2023-5366 | MEDIUM | 5.5 | 0.4% | Oct 6, 2023 | A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass Op... |
| CVE-2023-44384 | MEDIUM | 4.1 | 0.4% | Oct 6, 2023 | Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automati... |
| CVE-2023-23371 | MEDIUM | 4.4 | 0.1% | Oct 6, 2023 | A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If explo... |
| CVE-2023-23370 | MEDIUM | 4.4 | 0.2% | Oct 6, 2023 | An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the ... |
| CVE-2023-23366 | MEDIUM | 6.5 | 0.6% | Oct 6, 2023 | A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au... |
| CVE-2023-23365 | MEDIUM | 6.5 | 0.6% | Oct 6, 2023 | A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au... |
| CVE-2023-42445 | MEDIUM | 5.3 | 0.7% | Oct 6, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when ... |
| CVE-2023-44771 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code ... |
| CVE-2023-44770 | MEDIUM | 5.4 | 0.6% | Oct 6, 2023 | A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a... |
| CVE-2023-44766 | MEDIUM | 4.8 | 0.6% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a cr... |
| CVE-2023-44765 | MEDIUM | 5.4 | 0.6% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an at... |
| CVE-2023-44764 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installatio... |
| CVE-2023-44762 | MEDIUM | 5.4 | 0.6% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute ar... |
| CVE-2023-44761 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 thr... |
| CVE-2023-44758 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary cod... |
| CVE-2023-4469 | MEDIUM | 5.3 | 0.5% | Oct 6, 2023 | The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missi... |
| CVE-2023-45245 | MEDIUM | 5.5 | 0.2% | Oct 6, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux... |
| CVE-2023-45243 | MEDIUM | 5.5 | 0.2% | Oct 5, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protec... |
| CVE-2023-45242 | MEDIUM | 5.5 | 0.2% | Oct 5, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now