2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36118 | MEDIUM | 5.4 | 0.7% | Aug 1, 2023 | Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arb... |
| CVE-2023-34869 | MEDIUM | 6.1 | 0.3% | Aug 1, 2023 | PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /... |
| CVE-2023-33564 | MEDIUM | 6.1 | 0.4% | Aug 1, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Boo... |
| CVE-2023-33560 | MEDIUM | 6.1 | 0.4% | Aug 1, 2023 | There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking C... |
| CVE-2023-31426 | MEDIUM | 6.5 | 0.5% | Aug 1, 2023 | The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 ... |
| CVE-2023-31429 | MEDIUM | 5.5 | 0.2% | Aug 1, 2023 | Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “c... |
| CVE-2023-20583 | MEDIUM | 4.7 | 0.3% | Aug 1, 2023 | A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU po... |
| CVE-2023-38560 | MEDIUM | 5.5 | 0.3% | Aug 1, 2023 | An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local ... |
| CVE-2023-38559 | MEDIUM | 5.5 | 0.4% | Aug 1, 2023 | A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a ... |
| CVE-2023-36211 | MEDIUM | 5.4 | 0.4% | Aug 1, 2023 | The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with ce... |
| CVE-2023-4054 | MEDIUM | 5.5 | 0.2% | Aug 1, 2023 | When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only... |
| CVE-2023-4053 | MEDIUM | 6.5 | 0.7% | Aug 1, 2023 | A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, ... |
| CVE-2023-4052 | MEDIUM | 6.5 | 0.6% | Aug 1, 2023 | The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that d... |
| CVE-2023-4049 | MEDIUM | 5.9 | 0.6% | Aug 1, 2023 | Race conditions in reference counting code were found through code inspection. These could have resulted in potentially ... |
| CVE-2023-4046 | MEDIUM | 5.3 | 1.0% | Aug 1, 2023 | In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in i... |
| CVE-2023-4045 | MEDIUM | 5.3 | 0.5% | Aug 1, 2023 | Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from anot... |
| CVE-2023-38357 | MEDIUM | 5.3 | 3.1% | Aug 1, 2023 | Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a... |
| CVE-2023-23548 | MEDIUM | 6.1 | 0.4% | Aug 1, 2023 | Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30. |
| CVE-2023-37496 | MEDIUM | 5.4 | 0.3% | Aug 1, 2023 | HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a vi... |
| CVE-2023-3462 | MEDIUM | 5.3 | 0.6% | Jul 31, 2023 | HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker m... |
| CVE-2023-38989 | MEDIUM | 4.3 | 0.3% | Jul 31, 2023 | An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrar... |
| CVE-2023-4010 | MEDIUM | 4.6 | 0.5% | Jul 31, 2023 | A flaw was found in the USB Host Controller Driver framework in the Linux kernel. The usb_giveback_urb function has a lo... |
| CVE-2023-3817 | MEDIUM | 5.3 | 2.6% | Jul 31, 2023 | Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use ... |
| CVE-2023-37580 | MEDIUM | 6.1 | 59.0% | Jul 31, 2023 | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. |
| CVE-2023-34917 | MEDIUM | 6.1 | 0.4% | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now