2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38344 | MEDIUM | 6.5 | 1.0% | Sep 21, 2023 | An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFil... |
| CVE-2023-41991 | MEDIUM | 5.5 | 4.5% | Sep 21, 2023 | A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal... |
| CVE-2023-42806 | MEDIUM | 6.5 | 0.4% | Sep 21, 2023 | Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{ci... |
| CVE-2023-42458 | MEDIUM | 5.4 | 0.6% | Sep 21, 2023 | Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin... |
| CVE-2023-41048 | MEDIUM | 5.4 | 0.5% | Sep 21, 2023 | plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity conten... |
| CVE-2023-40183 | MEDIUM | 5.3 | 0.6% | Sep 21, 2023 | DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability ... |
| CVE-2023-43309 | MEDIUM | 4.8 | 0.4% | Sep 21, 2023 | There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input ... |
| CVE-2023-4753 | MEDIUM | 5.5 | 0.1% | Sep 21, 2023 | OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the err... |
| CVE-2023-5104 | MEDIUM | 6.5 | 0.6% | Sep 21, 2023 | Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0. |
| CVE-2023-4292 | MEDIUM | 5.3 | 0.4% | Sep 21, 2023 | Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a SQL injection v... |
| CVE-2023-39252 | MEDIUM | 5.9 | 0.3% | Sep 21, 2023 | Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated a... |
| CVE-2023-36234 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in d... |
| CVE-2023-38876 | MEDIUM | 6.1 | 0.7% | Sep 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to ex... |
| CVE-2023-38875 | MEDIUM | 6.1 | 0.8% | Sep 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to ex... |
| CVE-2023-22024 | MEDIUM | 5.5 | 0.2% | Sep 20, 2023 | In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6... |
| CVE-2023-42334 | MEDIUM | 6.5 | 0.6% | Sep 20, 2023 | An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalat... |
| CVE-2023-40930 | MEDIUM | 6.8 | 1.2% | Sep 20, 2023 | An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mount... |
| CVE-2023-39052 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted m... |
| CVE-2023-39045 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send cra... |
| CVE-2023-38718 | MEDIUM | 5.3 | 0.4% | Sep 20, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, ... |
| CVE-2023-43377 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers... |
| CVE-2023-43376 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute a... |
| CVE-2023-40368 | MEDIUM | 4.4 | 0.2% | Sep 20, 2023 | IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the admi... |
| CVE-2023-39041 | MEDIUM | 6.5 | 0.4% | Sep 20, 2023 | An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted mess... |
| CVE-2023-40618 | MEDIUM | 6.1 | 0.5% | Sep 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visu... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now