2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39067 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a cra... |
| CVE-2023-41000 | MEDIUM | 5.5 | 0.3% | Sep 11, 2023 | GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.... |
| CVE-2023-4630 | MEDIUM | 4.3 | 0.4% | Sep 11, 2023 | An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting fr... |
| CVE-2023-40786 | MEDIUM | 5.4 | 0.3% | Sep 11, 2023 | HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen. |
| CVE-2023-36980 | MEDIUM | 5.3 | 0.4% | Sep 11, 2023 | An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casin... |
| CVE-2023-4581 | MEDIUM | 4.3 | 0.5% | Sep 11, 2023 | Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be down... |
| CVE-2023-4580 | MEDIUM | 6.5 | 0.4% | Sep 11, 2023 | Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sen... |
| CVE-2023-4578 | MEDIUM | 6.5 | 0.5% | Sep 11, 2023 | When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErro... |
| CVE-2023-4577 | MEDIUM | 6.5 | 0.6% | Sep 11, 2023 | When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to... |
| CVE-2023-4575 | MEDIUM | 6.5 | 0.6% | Sep 11, 2023 | When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been cre... |
| CVE-2023-4574 | MEDIUM | 6.5 | 0.6% | Sep 11, 2023 | When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been cr... |
| CVE-2023-4104 | MEDIUM | 5.5 | 0.4% | Sep 11, 2023 | An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user ... |
| CVE-2023-4573 | MEDIUM | 6.5 | 0.5% | Sep 11, 2023 | When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a u... |
| CVE-2023-35845 | MEDIUM | 4.7 | 0.1% | Sep 11, 2023 | Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file use... |
| CVE-2023-40040 | MEDIUM | 5.3 | 0.5% | Sep 11, 2023 | An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacke... |
| CVE-2023-42467 | MEDIUM | 5.5 | 0.4% | Sep 11, 2023 | QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_... |
| CVE-2023-4879 | MEDIUM | 4.8 | 0.3% | Sep 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git. |
| CVE-2023-4878 | MEDIUM | 5.4 | 0.3% | Sep 10, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-4870 | MEDIUM | 6.1 | 0.6% | Sep 10, 2023 | A vulnerability classified as problematic has been found in SourceCodester Contact Manager App 1.0. This affects an unkn... |
| CVE-2023-4864 | MEDIUM | 6.1 | 0.5% | Sep 9, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Take-Note App 1.0. This affects an unk... |
| CVE-2023-4875 | MEDIUM | 5.7 | 0.5% | Sep 9, 2023 | Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12 |
| CVE-2023-4874 | MEDIUM | 6.5 | 0.7% | Sep 9, 2023 | Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12 |
| CVE-2023-4847 | MEDIUM | 6.1 | 0.6% | Sep 9, 2023 | A vulnerability classified as problematic has been found in SourceCodester Simple Book Catalog App 1.0. Affected is an u... |
| CVE-2023-4838 | MEDIUM | 5.4 | 0.3% | Sep 9, 2023 | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode... |
| CVE-2023-41564 | MEDIUM | 6.1 | 1.0% | Sep 8, 2023 | An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute ar... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now