2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26149 | MEDIUM | 6.1 | 0.6% | Sep 28, 2023 | Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-inp... |
| CVE-2023-38873 | MEDIUM | 6.5 | 0.6% | Sep 28, 2023 | The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also ... |
| CVE-2023-38871 | MEDIUM | 5.3 | 0.6% | Sep 28, 2023 | The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login ... |
| CVE-2023-41447 | MEDIUM | 6.1 | 0.8% | Sep 28, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41446 | MEDIUM | 6.1 | 0.8% | Sep 28, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-5244 | MEDIUM | 6.1 | 1.1% | Sep 28, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-43233 | MEDIUM | 6.1 | 0.3% | Sep 27, 2023 | A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to... |
| CVE-2023-43191 | MEDIUM | 5.4 | 0.3% | Sep 27, 2023 | SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comment... |
| CVE-2023-41453 | MEDIUM | 6.1 | 0.8% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41451 | MEDIUM | 6.1 | 0.8% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41448 | MEDIUM | 6.1 | 0.8% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41445 | MEDIUM | 6.1 | 0.7% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-4066 | MEDIUM | 5.5 | 0.2% | Sep 27, 2023 | A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, de... |
| CVE-2023-40026 | MEDIUM | 4.3 | 0.5% | Sep 27, 2023 | Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at l... |
| CVE-2023-44048 | MEDIUM | 5.4 | 0.4% | Sep 27, 2023 | Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category. |
| CVE-2023-4523 | MEDIUM | 6.1 | 0.3% | Sep 27, 2023 | Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which co... |
| CVE-2023-42822 | MEDIUM | 6.5 | 0.6% | Sep 27, 2023 | xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked... |
| CVE-2023-20268 | MEDIUM | 4.7 | 0.2% | Sep 27, 2023 | A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticate... |
| CVE-2023-20253 | MEDIUM | 5.5 | 0.2% | Sep 27, 2023 | A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenti... |
| CVE-2023-20251 | MEDIUM | 5.3 | 0.2% | Sep 27, 2023 | A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticat... |
| CVE-2023-20202 | MEDIUM | 6.5 | 0.2% | Sep 27, 2023 | A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers coul... |
| CVE-2023-20179 | MEDIUM | 5.4 | 0.4% | Sep 27, 2023 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c... |
| CVE-2023-20109 | MEDIUM | 6.6 | 2.3% | Sep 27, 2023 | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Soft... |
| CVE-2023-5197 | MEDIUM | 6.6 | 0.4% | Sep 27, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr... |
| CVE-2023-5192 | MEDIUM | 6.5 | 0.8% | Sep 27, 2023 | Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now