2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49117 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | PowerCMS (6 Series, 5 Series, and 4 Series) contains a stored cross-site scripting vulnerability. If this vulnerability ... |
| CVE-2023-28616 | HIGH | 7.5 | 0.3% | Dec 26, 2023 | An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x... |
| CVE-2023-27150 | MEDIUM | 5.4 | 0.4% | Dec 26, 2023 | openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of ... |
| CVE-2023-7111 | CRITICAL | 9.8 | 0.6% | Dec 26, 2023 | A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. Affected is... |
| CVE-2023-38321 | HIGH | 7.5 | 1.1% | Dec 25, 2023 | OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial... |
| CVE-2023-49954 | CRITICAL | 9.8 | 2.2% | Dec 25, 2023 | The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search stri... |
| CVE-2023-49944 | MEDIUM | 6.7 | 0.2% | Dec 25, 2023 | The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local adm... |
| CVE-2023-49226 | HIGH | 7.2 | 3.4% | Dec 25, 2023 | An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administ... |
| CVE-2023-48652 | MEDIUM | 4.3 | 0.2% | Dec 25, 2023 | Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/s... |
| CVE-2023-38826 | MEDIUM | 6.1 | 0.4% | Dec 25, 2023 | A Cross Site Scripting (XSS) vulnerability exists in Follet Learning Solutions Destiny through 20.0_1U. via the handlewp... |
| CVE-2023-36486 | HIGH | 7.2 | 0.9% | Dec 25, 2023 | The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system comm... |
| CVE-2023-36485 | HIGH | 7.2 | 0.8% | Dec 25, 2023 | The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system comm... |
| CVE-2023-31224 | CRITICAL | 9.8 | 0.6% | Dec 25, 2023 | There is broken access control during authentication in Jamf Pro Server before 10.46.1. |
| CVE-2023-47247 | MEDIUM | 4.3 | 0.3% | Dec 25, 2023 | In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base artic... |
| CVE-2023-47091 | HIGH | 7.5 | 0.5% | Dec 25, 2023 | An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through... |
| CVE-2023-37188 | HIGH | 7.5 | 0.8% | Dec 25, 2023 | C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/b... |
| CVE-2023-37187 | HIGH | 7.5 | 0.8% | Dec 25, 2023 | C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. ... |
| CVE-2023-37186 | HIGH | 7.5 | 0.8% | Dec 25, 2023 | C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memse... |
| CVE-2023-37185 | HIGH | 7.5 | 0.8% | Dec 25, 2023 | C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/b... |
| CVE-2023-31297 | MEDIUM | 4.8 | 0.3% | Dec 25, 2023 | An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Na... |
| CVE-2023-28872 | HIGH | 8.8 | 0.8% | Dec 25, 2023 | Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privile... |
| CVE-2023-51772 | HIGH | 8.8 | 0.5% | Dec 25, 2023 | One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct... |
| CVE-2023-49328 | HIGH | 7.2 | 1.0% | Dec 25, 2023 | On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated syst... |
| CVE-2023-48654 | CRITICAL | 9.8 | 1.0% | Dec 25, 2023 | One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct... |
| CVE-2023-40236 | MEDIUM | 5.3 | 0.4% | Dec 25, 2023 | In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, whic... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now