2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51105 | HIGH | 7.5 | 0.9% | Dec 26, 2023 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompr... |
| CVE-2023-51104 | HIGH | 7.5 | 0.9% | Dec 26, 2023 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_... |
| CVE-2023-51103 | HIGH | 7.5 | 0.9% | Dec 26, 2023 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_... |
| CVE-2023-49949 | HIGH | 8.1 | 0.6% | Dec 26, 2023 | Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit... |
| CVE-2023-50968 | HIGH | 7.5 | 63.4% | Dec 26, 2023 | Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri cal... |
| CVE-2023-5180 | HIGH | 7.8 | 0.2% | Dec 26, 2023 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used... |
| CVE-2023-51363 | MEDIUM | 6.5 | 0.3% | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's ... |
| CVE-2023-50339 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v... |
| CVE-2023-50332 | MEDIUM | 6.5 | 0.4% | Dec 26, 2023 | Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6... |
| CVE-2023-50294 | MEDIUM | 6.5 | 0.3% | Dec 26, 2023 | The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As ... |
| CVE-2023-50175 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/ma... |
| CVE-2023-49807 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this ... |
| CVE-2023-49779 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerabil... |
| CVE-2023-49598 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0... |
| CVE-2023-49119 | MEDIUM | 5.4 | 0.4% | Dec 26, 2023 | Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerabili... |
| CVE-2023-47215 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prio... |
| CVE-2023-46711 | MEDIUM | 4.6 | 0.2% | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the p... |
| CVE-2023-46699 | MEDIUM | 4.3 | 0.2% | Dec 26, 2023 | Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0... |
| CVE-2023-46681 | HIGH | 7.8 | 0.3% | Dec 26, 2023 | Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ve... |
| CVE-2023-45741 | MEDIUM | 6.8 | 0.3% | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute a... |
| CVE-2023-45740 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If th... |
| CVE-2023-45737 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin... |
| CVE-2023-42436 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this ... |
| CVE-2023-51654 | MEDIUM | 5.5 | 0.2% | Dec 26, 2023 | Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions ... |
| CVE-2023-50297 | MEDIUM | 6.1 | 0.4% | Dec 26, 2023 | Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to r... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now