2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25837 | HIGH | 8.4 | 0.9% | Jul 21, 2023 | There is a Cross‑Site Scripting (XSS) vulnerability in Esri ArcGIS Enterprise Sites versions 10.9 and below that may all... |
| CVE-2023-3813 | HIGH | 7.5 | 1.0% | Jul 21, 2023 | The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.... |
| CVE-2023-3808 | HIGH | 8.8 | 0.6% | Jul 21, 2023 | A vulnerability was found in Hospital Management System 1.0 and classified as critical. Affected by this issue is some u... |
| CVE-2023-3807 | HIGH | 8.8 | 0.6% | Jul 21, 2023 | A vulnerability has been found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by t... |
| CVE-2023-25835 | HIGH | 8.4 | 0.7% | Jul 21, 2023 | There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS Sites versions 11.1 and below that ... |
| CVE-2023-3797 | HIGH | 8.8 | 0.8% | Jul 20, 2023 | A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention... |
| CVE-2023-3796 | HIGH | 8.8 | 0.5% | Jul 20, 2023 | A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0. Affected by this is... |
| CVE-2023-37650 | HIGH | 8.8 | 0.5% | Jul 20, 2023 | A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Admi... |
| CVE-2023-37649 | HIGH | 7.5 | 0.7% | Jul 20, 2023 | Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access ... |
| CVE-2023-34625 | HIGH | 8.1 | 0.9% | Jul 20, 2023 | ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mech... |
| CVE-2023-30200 | HIGH | 7.5 | 0.6% | Jul 20, 2023 | In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Adv... |
| CVE-2023-37601 | HIGH | 7.5 | 1.0% | Jul 20, 2023 | Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the componen... |
| CVE-2023-31462 | HIGH | 8.8 | 0.9% | Jul 20, 2023 | An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writa... |
| CVE-2023-31461 | HIGH | 7.5 | 0.8% | Jul 20, 2023 | Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed au... |
| CVE-2023-34966 | HIGH | 7.5 | 62.0% | Jul 20, 2023 | An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC ... |
| CVE-2023-37290 | HIGH | 7.5 | 0.6% | Jul 20, 2023 | InfoDoc Document On-line Submission and Approval System lacks sufficient restrictions on the available tags within its ... |
| CVE-2023-37362 | HIGH | 8.8 | 0.5% | Jul 19, 2023 | Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing cred... |
| CVE-2023-36853 | HIGH | 7.8 | 0.2% | Jul 19, 2023 | In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containin... |
| CVE-2023-34429 | HIGH | 7.5 | 0.5% | Jul 19, 2023 | Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending... |
| CVE-2023-34394 | HIGH | 7.8 | 0.2% | Jul 19, 2023 | In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or d... |
| CVE-2023-32657 | HIGH | 7.5 | 0.4% | Jul 19, 2023 | Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with... |
| CVE-2023-26217 | HIGH | 8.8 | 0.6% | Jul 19, 2023 | The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerabili... |
| CVE-2023-37899 | HIGH | 7.5 | 1.0% | Jul 19, 2023 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socke... |
| CVE-2023-37276 | HIGH | 7.5 | 1.4% | Jul 19, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled w... |
| CVE-2023-3467 | HIGH | 8 | 2.1% | Jul 19, 2023 | Privilege Escalation to root administrator (nsroot) |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now