2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40306 | MEDIUM | 6.1 | 0.3% | Sep 8, 2023 | SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a maliciou... |
| CVE-2023-24965 | MEDIUM | 5.3 | 0.4% | Sep 8, 2023 | IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM... |
| CVE-2023-41318 | MEDIUM | 5.4 | 0.4% | Sep 8, 2023 | matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected vers... |
| CVE-2023-32332 | MEDIUM | 5.4 | 0.5% | Sep 8, 2023 | IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection... |
| CVE-2023-41575 | MEDIUM | 5.4 | 0.4% | Sep 8, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 a... |
| CVE-2023-41338 | MEDIUM | 5.3 | 0.5% | Sep 8, 2023 | Fiber is an Express inspired web framework built in the go language. Versions of gofiber prior to 2.49.2 did not properl... |
| CVE-2023-39712 | MEDIUM | 6.1 | 0.6% | Sep 8, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta... |
| CVE-2023-28010 | MEDIUM | 5.3 | 0.3% | Sep 8, 2023 | In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target fu... |
| CVE-2023-4843 | MEDIUM | 4.8 | 0.3% | Sep 8, 2023 | Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Busines... |
| CVE-2023-39319 | MEDIUM | 6.1 | 0.8% | Sep 8, 2023 | The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" ... |
| CVE-2023-39318 | MEDIUM | 6.1 | 0.8% | Sep 8, 2023 | The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <sc... |
| CVE-2023-39676 | MEDIUM | 6.1 | 1.3% | Sep 8, 2023 | FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi... |
| CVE-2023-39076 | MEDIUM | 4.6 | 0.3% | Sep 8, 2023 | Injecting random data into the USB memory area on a General Motors (GM) Chevrolet Equinox 2021 Software. 2021.03.26 (bui... |
| CVE-2023-4777 | MEDIUM | 4.3 | 0.3% | Sep 8, 2023 | An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with g... |
| CVE-2023-41775 | MEDIUM | 5.5 | 0.2% | Sep 8, 2023 | Improper access control vulnerability in 'direct' Desktop App for macOS ver 2.6.0 and earlier allows a local attacker to... |
| CVE-2023-34041 | MEDIUM | 5.3 | 0.4% | Sep 8, 2023 | Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthent... |
| CVE-2023-32470 | MEDIUM | 5.5 | 0.2% | Sep 8, 2023 | Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulner... |
| CVE-2023-37367 | MEDIUM | 5.3 | 0.4% | Sep 8, 2023 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Ex... |
| CVE-2023-40584 | MEDIUM | 6.5 | 1.2% | Sep 7, 2023 | Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug wher... |
| CVE-2023-41646 | MEDIUM | 5.3 | 0.4% | Sep 7, 2023 | Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the ... |
| CVE-2023-41161 | MEDIUM | 5.4 | 0.4% | Sep 7, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary w... |
| CVE-2023-41316 | MEDIUM | 5.4 | 0.4% | Sep 7, 2023 | Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails wi... |
| CVE-2023-20194 | MEDIUM | 4.9 | 0.5% | Sep 7, 2023 | A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the... |
| CVE-2023-20193 | MEDIUM | 6.7 | 0.2% | Sep 7, 2023 | A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, ... |
| CVE-2023-37798 | MEDIUM | 5.4 | 0.5% | Sep 7, 2023 | A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now