2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38697 | MEDIUM | 5.3 | 0.6% | Aug 4, 2023 | protocol-http1 provides a low-level implementation of the HTTP/1 protocol. RFC 9112 Section 7.1 defined the format of ch... |
| CVE-2023-38695 | MEDIUM | 6.5 | 0.8% | Aug 4, 2023 | cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possib... |
| CVE-2023-38332 | MEDIUM | 6.5 | 3.0% | Aug 4, 2023 | Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitiv... |
| CVE-2023-0264 | MEDIUM | 5 | 1.3% | Aug 4, 2023 | A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authen... |
| CVE-2023-39112 | MEDIUM | 6.5 | 0.6% | Aug 4, 2023 | ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel. |
| CVE-2023-38691 | MEDIUM | 6.5 | 0.4% | Aug 4, 2023 | matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 a... |
| CVE-2023-38964 | MEDIUM | 6.1 | 1.1% | Aug 4, 2023 | Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2023-38686 | MEDIUM | 5.3 | 0.2% | Aug 4, 2023 | Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send email... |
| CVE-2023-4135 | MEDIUM | 6.5 | 0.4% | Aug 4, 2023 | A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate a... |
| CVE-2023-34038 | MEDIUM | 5.3 | 0.4% | Aug 4, 2023 | VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be abl... |
| CVE-2023-34037 | MEDIUM | 5.3 | 0.4% | Aug 4, 2023 | VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able... |
| CVE-2023-4002 | MEDIUM | 6.5 | 0.5% | Aug 4, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting... |
| CVE-2023-39343 | MEDIUM | 4.3 | 0.5% | Aug 4, 2023 | Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form... |
| CVE-2023-38991 | MEDIUM | 5.4 | 0.4% | Aug 4, 2023 | An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbi... |
| CVE-2023-36159 | MEDIUM | 6.1 | 0.6% | Aug 4, 2023 | Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers... |
| CVE-2023-36158 | MEDIUM | 6.1 | 0.6% | Aug 4, 2023 | Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run... |
| CVE-2023-36141 | MEDIUM | 5.3 | 0.5% | Aug 4, 2023 | User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, w... |
| CVE-2023-36138 | MEDIUM | 6.1 | 0.4% | Aug 4, 2023 | PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview... |
| CVE-2023-36137 | MEDIUM | 6.1 | 0.3% | Aug 4, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduli... |
| CVE-2023-37501 | MEDIUM | 6.1 | 0.3% | Aug 3, 2023 | A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user... |
| CVE-2023-37500 | MEDIUM | 6.1 | 0.3% | Aug 3, 2023 | A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacke... |
| CVE-2023-37499 | MEDIUM | 6.1 | 0.3% | Aug 3, 2023 | A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An a... |
| CVE-2023-30958 | MEDIUM | 6.1 | 0.3% | Aug 3, 2023 | A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundr... |
| CVE-2023-30952 | MEDIUM | 4.3 | 0.4% | Aug 3, 2023 | A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the... |
| CVE-2023-30951 | MEDIUM | 6.5 | 0.4% | Aug 3, 2023 | The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE). |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now